RondoDox, also referred to as rondo or the Rondo botnet, is a botnet observed conducting multi-phase exploitation campaigns against a mix of enterprise services, AI-related infrastructure, consumer networking equipment, and internet-facing applications. Available reporting ties observed operations to infrastructure assessed to be operating from New Zealand, with activity suggesting use of compromised residential routers and rotating staging or command infrastructure. Observed RondoDox activity spans at least three phases. In earlier phases, the botnet targeted enterprise-facing services using fileless exploitation patterns and header-based payload delivery. Documented tradecraft includes attempts to exploit Log4Shell (CVE-2021-44228) with obfuscated payloads embedded across the User-Agent and multiple HTTP headers, consistent with header-spray delivery intended to maximize execution opportunities and evade simplistic detection. The actor also targeted the ShadowRay-related /api/jobs/ attack surface associated with CVE-2023-48022. Later phases expanded to consumer-router exploitation, including LB-LINK command injection and ASUS AsusWRT NVRAM manipulation, indicating operational flexibility across both enterprise and edge-device targets. Separate reporting also links the botnet to exploitation attempts against SmartBI via CVE-2023-7305. The campaign demonstrates reconnaissance and opportunistic initial-access behavior through active exploitation of known vulnerabilities, followed by post-exploitation payload staging and infrastructure rotation. Its use of fileless techniques, obfuscated header injection, and shifting infrastructure indicates a higher degree of operational maturity than typical low-end commodity botnet activity. High-confidence aliases include rondo and Rondo botnet; RondoDox appears to be the most distinctive and recognizable name for the cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sophisticated botnet campaign conducting broad-spectrum exploitation against enterprise web applications, AI frameworks, and consumer routers, using fileless payloads, rotating C2 infrastructure, and compromised residential routers for scanning.
Observed targeting CVE-2023-7305 (SmartBI RMIServlet unrestricted file upload leading to remote code execution).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.