RondoDox persistent IoT and web app botnet campaign
Campaign
Summary
Hide ▲
Show ▼
RondoDox ran a nine-month campaign against IoT devices and web applications to expand botnet enrollment. The operation began in March-April 2025 with initial reconnaissance and manual vulnerability scanning against exposed systems. By December 2025, the actors were using React2Shell (CVE-2025-55182) against vulnerable Next.js servers, and the payloads included cryptocurrency miners, a botnet loader and health checker, and a Mirai variant. CloudSEK urged defenders to update Next.js and harden IoT exposure.
Cases
Related Happenings
TA416 European government espionage campaign
Campaign
H score32
First: 01.04.2026 15:05
Last: 01.04.2026 15:05
Sources 1
About this happening:
TA416 has resumed cyber espionage activity, targeting European governments and EU/NATO diplomatic missions with a renewed malware-delivery operation that raises cross-...
TA416 European government espionage campaign
CampaignAbout this happening: TA416 has resumed cyber espionage activity, targeting European governments and EU/NATO diplomatic missions with a renewed malware-delivery operation that raises cross-...
Latest development: 03.04.2026 20:34
TA416 expanded its espionage campaign to Middle Eastern government and diplomatic entities after the outbreak of the U.S.-Israel-Iran conflict in late February 2026, while linking to archives hosted on Google Drive or a compromised SharePoint instance to refine its PlugX delivery chain and collect regional intelligence.
MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
Campaign
H score42
First: 06.03.2026 12:23
Last: 06.03.2026 12:23
Sources 1
About this happening:
MuddyWater (Seedworm) is running a state-linked intrusion campaign that has embedded itself in U.S. banks, airports, a non-profit, and an Israeli software company arm,...
MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm
CampaignAbout this happening: MuddyWater (Seedworm) is running a state-linked intrusion campaign that has embedded itself in U.S. banks, airports, a non-profit, and an Israeli software company arm,...
Ariomex leaked database exposing 11,826 verified user records
Data Leak
H score69
First: 03.03.2026 16:30
Last: 03.03.2026 16:30
Sources 1
About this happening:
A newly obtained Ariomex database exposed 11,826 verified user records, creating a concrete view of activity tied to sanctions evasion and large-scale capital transf...
Ariomex leaked database exposing 11,826 verified user records
Data LeakAbout this happening: A newly obtained Ariomex database exposed 11,826 verified user records, creating a concrete view of activity tied to sanctions evasion and large-scale capital transf...
React2Shell (CVE-2025-55182) mass scanning and exploitation wave
Exploitation Wave
H score89
First: 20.02.2026 23:07
Last: 20.02.2026 23:07
Sources 1
About this happening:
CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...
React2Shell (CVE-2025-55182) mass scanning and exploitation wave
Exploitation WaveAbout this happening: CVE-2025-55182 (React2Shell) was publicly disclosed on December 3, 2025 as a CVSS 10 remote code execution flaw in React Server Components. Since then, the vulnera...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
Campaign
H score33
First: 11.02.2026 00:17
Last: 11.02.2026 00:17
Sources 1
About this happening:
Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms
CampaignAbout this happening: Separate analyses described North Korea-linked operators associated with UNC1069 and BlueNoroff using social engineering against cryptocurrency targets and a fin...
Timeline
-
01.01.2026 11:19 2 articles · 6mo ago
RondoDox persistent IoT and web app botnet campaign
Initial DisclosureIn March-April 2025, the operation began with initial reconnaissance and manual vulnerability scanning against exposed IoT devices and web applications.
Show sources
- RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers — thehackernews.com — 01.01.2026 11:19
- RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers — thehackernews.com — 01.01.2026 11:19