The increase in activity is driven primarily by a new variant of the influenza A virus known as H3N2 subclade K.
December 2025, the RondoDox botnet operators have been targeting Next.js servers impacted by the React2Shell vulnerability.