Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

RondoDox botnet pressure on IoT devices and web apps

Updated 01.01.2026 11:19
Case score 58
Members 1 First seen 01.01.2026 11:19 Latest activity 01.01.2026 11:19

Overview

RondoDox has sustained a persistent botnet campaign against exposed **IoT devices** and **web applications**, and by December 2025 it was using **React Server Components (CVE-2025-55182)** alongside other N-day flaws to reach internet-facing systems. The activity progressed from March-April reconnaissance and manual scanning to daily mass probing and hourly automated deployment, showing a more automated and scalable pattern. Defensive guidance centers on updating **Next.js** where applicable, segmenting IoT devices into VLANs, deploying WAFs, and watching for suspicious process execution or known C2 activity. Available evidence does not quantify reach, but observed activity spans the United States, Germany, France, and India and remained active in December 2025.
Latest development

RondoDox persistent IoT and web app botnet campaign

In **March-April 2025**, the operation began with **initial reconnaissance and manual vulnerability scanning** against exposed IoT devices and web applications.

Signals

Impact signals
CVEs/products
Status
Threat context

Malware & tooling context

2 families · 3 tools
Tools

Member happenings

Campaign RondoDox persistent IoT and web app botnet campaign
Updated 01.01.2026 11:19 Lead Contribution 58
Campaign Active

**RondoDox** ran a **nine-month** campaign against **IoT devices** and **web applications** to expand botnet enrollment. The operation began in **March-April 2025** with initial reconnaissance and manual vulnerability scanning against exposed systems. By **December 2025**, the actors were using **React2Shell (CVE-2025-55182)** against vulnerable **Next.js** servers, and the payloads included **cryptocurrency miners**, a botnet loader and health checker, and a **Mirai** variant. **CloudSEK** urged defenders to update **Next.js** and harden IoT exposure.