RondoDox Botnet Exploits React2Shell Flaw to Hijack IoT Devices and Servers

1 min read
Source: The Hacker News
RondoDox Botnet Exploits React2Shell Flaw to Hijack IoT Devices and Servers
Photo: The Hacker News
TL;DR Summary

Cybersecurity researchers have uncovered a nine-month campaign where the RondoDox botnet exploited the critical React2Shell vulnerability (CVE-2025-55182) to hijack IoT devices and web servers, deploying malware, cryptocurrency miners, and Mirai variants, with the threat still active as of December 2025. Organizations are urged to update vulnerable software, segment IoT devices, and enhance monitoring to prevent infection.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

87%

42956 words

Want the full story? Read the original article

Read on The Hacker News