RondoDox botnet exploits React2Shell flaw to breach Next.js servers
The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. [...]
Stay updated on Cryptominer threats. Explore news, trends, and insights on cryptocurrency mining malware in information security. Stay safe online.
Search across headline titles and summaries.
Background for this topic.
Cryptominer is a type of software designed to use a device's computational resources to mine cryptocurrency. In the realm of information security, cryptominers can pose significant threats when used maliciously. Cybercriminals often deploy cryptomining malware on unsuspecting users' devices without their consent to profit off the mined digital currency, capitalizing on the resources of others.
The presence of unauthorized cryptomining activities on a system can lead to a myriad of problems, including degraded system performance, increased energy consumption, and potential overheating issues. Information security efforts aim to detect, prevent, and mitigate the risks associated with cryptomining malware to protect users and enterprises from such exploits. Addressing cryptominer threats is a continuous challenge, as attackers constantly evolve their tactics to circumvent security measures.
Weekly headline count for the current query.
The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. [...]
A financially motivated threat actor has been observed exploiting a recently disclosed remote code execution flaw affecting the Craft Content Management System (CMS) to deploy multiple payloads, including a cryptocurrency miner, a loader dubbed Mimo Loader, and residential proxyware
Threat actors are exploiting a critical remote command execution vulnerability, tracked as CVE-2024-50603, in Aviatrix Controller instances to install backdoors and crypto miners. [...]
We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.