RondoDoX Botnet is a botnet that multiple sources reported as being involved in increased exploitation activity against CVE-2025-24893, a critical unauthenticated remote code execution vulnerability in XWiki Platform’s xwiki-platform-search-solr-ui component via the SolrSearchMacros feature. The vulnerability affects XWiki versions >= 5.3-milestone-2 and < 15.10.11, and >= 16.0.0-rc-1 and < 16.4.1, and can be exploited by sending a specially crafted SolrSearchMacros request, potentially granting full control of the affected XWiki instance. Supporting reporting also states that the RondoDoX botnet weaponized the React2Shell vulnerability. Based on the provided content, the malware is associated with opportunistic exploitation of internet-exposed vulnerable applications. Potential impact from the XWiki exploitation activity includes system compromise, data breaches, and operational downtime. No additional high-confidence details on malware family lineage, propagation mechanism, payloads, or specific indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...include CVE-2024-3721, a medium-severity command injection vulnerability affecting TBK DVR-4104 and DVR-4216 DVRs
... successfully exploited multiple FortiWeb devices to deploy Sliver. This group also leveraged React2Shell (CVE-2025-55182) in order to deploy Sliver ... CloudSEK ... RondoDoX botnet ... weaponizing the latest Next.js vulnerability ... Next.js RCE became dominant attack vector in December 2025 ...
...and CVE-2024-12856, an operating
6 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RondoDoX Botnet is a botnet that leverages the React2Shell vulnerability for weaponization.
Botnet reported as being involved in active exploitation of CVE-2025-24893 (XWiki SolrSearchMacros unauthenticated RCE) against vulnerable XWiki instances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.