RondoDox is a Linux-focused botnet and threat cluster first observed in mid-2025 and commonly characterized as a Mirai-based variant or loader. It primarily targets internet-exposed IoT devices, end-of-life consumer routers, embedded Linux systems, and vulnerable web applications, using broad opportunistic mass exploitation across dozens of known vulnerabilities. Reported target classes include routers, DVRs, NVRs, CCTV systems, cameras, NAS appliances, gateways, web servers, and Next.js-based applications. The actor is notable for an "exploit shotgun" operating style: scanning widely, attempting many command-injection and remote-code-execution paths in parallel, and rapidly weaponizing newly disclosed flaws alongside older embedded-device vulnerabilities. Activity attributed to RondoDox includes exploitation of React2Shell (CVE-2025-55182), XWiki CVE-2025-24893, HPE OneView CVE-2025-37164, ShellShock (CVE-2014-6271), CVE-2023-1389, and CVE-2018-5999, among many others. Campaign reporting also links the botnet to exploitation of WordPress, Drupal, Struts 2, WebLogic, and other web-facing software as initial access paths. Operationally, RondoDox uses multi-stage infection chains. First-stage shell scripts fetch architecture-specific payloads for multiple CPU families, maximize compatibility through multiple download methods, and aggressively prepare the host by killing suspicious or competing processes, deleting prior infections, attempting to disable security controls, and clearing traces. Follow-on payloads have included Mirai-based botnet malware, loader and health-check components, and cryptocurrency miners. Persistence has been observed through scheduled task or cron-based mechanisms, and some reporting associates the actor with credential theft in addition to botnet enrollment, cryptomining, and distributed denial-of-service operations. RondoDox infrastructure has been described as fast-changing and operationally pragmatic, including use of compromised residential systems for distribution or hosting. The actor has been observed heavily targeting both IoT/edge devices and web application servers, including large-scale automated exploitation waves against vulnerable Next.js and HPE OneView deployments. Government, financial services, and industrial organizations have been specifically identified among targeted sectors in some campaigns, while broader activity remains highly opportunistic and indiscriminate. Known aliases include rondodox_botnet and rondodox_threat_actor. High-confidence reporting consistently places RondoDox in the financially motivated cybercriminal botnet ecosystem rather than as a state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
24 CVEs this actor has used in observed campaigns. 24 of them exploited in the wild.
The data shown below in Table 2 summarizes activity for October and November... CVE-2014-2321 18 0 (-18)
CVE-2014-6271, commonly known as the Shellshock vulnerability, remains one of the most notorious flaws in Unix-based systems. This vulnerability affects the Bash shell and allows attackers to execute arbitrary commands by injecting malicious code into environment variables.
CVEs such as CVE-2020-8958 (1,756 attempts) and CVE-2015-2051 (752 attempts) dominated the activity
The data shown below in Table 2 summarizes activity for October and November... CVE-2016-5674 30 0 (-30)
CVE-2017-10271 131 97 (-34)
19 more CVEs tied to this actor tracked in Mallory.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet exploiting CVE-2018-5999 in older ASUS routers to compromise Linux-based internet edge devices and conduct denial-of-service activity.
Linux-focused botnet activity exploiting vulnerable Asus routers and other end-of-life/IoT devices for DoS operations via mass exploitation and multi-stage infection chains.
A Linux-focused botnet active since mid-2025 that conducts DoS attacks and mass exploitation of end-of-life and IoT devices, including Asus routers, using numerous embedded CVEs and multi-stage infection chains.
Botnet activity tied to exploitation of the XWiki vulnerability CVE-2025-24893 in cloud intrusion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.