RHOMBUS is a Linux-based botnet malware family first publicly reported in 2020. It functions as an installer or dropper that establishes persistence on compromised systems, deploys a second-stage payload, and then uses infected hosts for distributed denial-of-service activity. Reported targeting has focused on Linux virtual private servers and IoT devices. Later reporting linked a 2025 Linux intrusion campaign to RHOMBUS through a dropper architecture described as identical to earlier RHOMBUS tooling and through shared command-and-control infrastructure characteristics. In that later activity, RHOMBUS-linked tradecraft overlapped with delivery of Linux malware used for persistence on compromised hosts, indicating that the RHOMBUS ecosystem has been associated not only with botnet operations but also with broader post-compromise tooling. The name RHOMBUS is the primary known designation for this malware and associated activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux-based botnet cluster linked by shared dropper architecture and overlapping command-and-control infrastructure with a 2025 OrBit-related campaign.
Campaign/botnet associated with a Linux installer/dropper architecture later seen reused by a 2025 OrBit infector; RHOMBUS malware persists on infected devices, drops second-stage payloads, and uses systems for DDoS activity, targeting VPS and IoT devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.