RondoDox is a Linux-focused botnet and threat actor cluster first observed in mid-2025 and commonly assessed as a Mirai-based variant or loader ecosystem. It primarily targets internet-exposed IoT devices, end-of-life consumer routers, embedded Linux systems, and vulnerable web applications, using broad opportunistic mass exploitation across numerous known vulnerabilities. Reporting has characterized its operating model as an "exploit shotgun" approach: scanning widely, attempting many exploits in parallel, and rapidly weaponizing newly disclosed flaws affecting consumer and enterprise-facing technologies. RondoDox has been linked to exploitation of vulnerabilities affecting routers, DVRs, NVRs, CCTV systems, NAS appliances, web servers, HPE OneView, XWiki, Ray, and React/Next.js deployments. It has been observed exploiting React2Shell, ShellShock, older embedded-device flaws, and critical router vulnerabilities, including campaigns against ASUS routers and large-scale automated exploitation of HPE OneView. The actor has also been associated with attempts to exploit Ray prior to public disclosure, although one reported implementation did not successfully bypass the target’s browser check. Operationally, RondoDox uses multi-stage infection chains. Initial access is typically achieved through unauthenticated remote code execution or command-injection flaws, followed by retrieval of first-stage shell scripts and architecture-specific Linux payloads. Its tooling has been reported to disable or weaken host defenses, kill suspicious or competing processes, remove rival malware, clear traces, and deploy binaries across multiple CPU architectures. Persistence has been established through cron-based mechanisms, and the malware has shown aggressive anti-competition behavior intended to monopolize compromised devices. The botnet’s post-compromise activity includes enrolling devices into distributed denial-of-service infrastructure, deploying cryptominers, and in some reporting, credential theft. It has also been described as a loader for Mirai-based payloads and other IoT malware families. Infrastructure usage has included compromised residential systems, and the actor appears to rotate delivery infrastructure and signature strings regularly. Targeting has been broad and opportunistic, but observed victim sectors include government, financial services, industrial organizations, and operators of internet-facing web applications and IoT estates. Known aliases include RondoDoX, RondoDox botnet, and related naming variants used to describe the malware and operator cluster. The dominant motivation is assessed as financial, driven by botnet monetization through DDoS-for-hire style activity, cryptomining, and related abuse of compromised infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The data shown below in Table 2 summarizes activity for October and November... CVE-2014-2321 18 0 (-18)
CVE-2014-6271, commonly known as the Shellshock vulnerability, remains one of the most notorious flaws in Unix-based systems. This vulnerability affects the Bash shell and allows attackers to execute arbitrary commands by injecting malicious code into environment variables.
CVEs such as CVE-2020-8958 (1,756 attempts) and CVE-2015-2051 (752 attempts) dominated the activity
The data shown below in Table 2 summarizes activity for October and November... CVE-2016-5674 30 0 (-30)
CVE-2017-10271 131 97 (-34)
19 more CVEs tied to this actor tracked in Mallory.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attempted exploitation activity targeting CVE-2025-62593 prior to public disclosure; the observed attempt did not successfully bypass Ray's browser check.
Botnet exploiting CVE-2018-5999 in older ASUS routers to compromise Linux-based internet edge devices and conduct denial-of-service activity.
Linux-focused botnet activity exploiting vulnerable Asus routers and other end-of-life/IoT devices for DoS operations via mass exploitation and multi-stage infection chains.
A Linux-focused botnet active since mid-2025 that conducts DoS attacks and mass exploitation of end-of-life and IoT devices, including Asus routers, using numerous embedded CVEs and multi-stage infection chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.