RondoDox Botnet: How 90,000+ Servers Were Hijacked Silently

Jan 16, 2026

90,000+ servers compromised. No ransomware. No alerts.
RondoDox exploited the Next.js React2Shell flaw to silently recruit unpatched apps into a botnet—deploying cryptominers and DDoS payloads. This is how modern botnets grow, and why app-layer bot protection matters.
For more insights on website and API security fundamentals, subscribe to our newsletter: https://bit.ly/4huCW7P
#RondoDox
#BotnetAttack
#CyberSecurity
#NextJS
#React2Shell
#BotProtection
#WebSecurity
#APIsecurity
#DDoS
#CloudSecurity