Rondo is a Linux-focused botnet and cryptomining malware operation observed exploiting internet-facing vulnerabilities for opportunistic compromise. It has been linked to mass exploitation activity against exposed services including GeoServer and vulnerable Node.js application stacks affected by CVE-2025-55182, as well as targeting of SmartBI through CVE-2023-7305. Reported intrusion chains show shell-script-based installation that retrieves additional components, including a propagation module and a cryptocurrency mining payload, indicating a monetization model centered on worm-like spread and illicit mining. Rondo has also been described alongside other botnet activity such as Mirai in broad, indiscriminate scanning and exploitation waves.
Observed behavior supports classification as a botnet with downloader characteristics. Campaigns attributed to Rondo use remote code execution vulnerabilities to execute shell commands that fetch and run installer scripts on compromised hosts. Those installers then deploy follow-on modules for propagation and mining. The malware has been associated with attacks on Linux systems and on a wide range of exposed Linux-based and embedded devices reachable through vulnerable web interfaces. Its operational pattern is consistent with automated exploitation at scale rather than narrowly targeted intrusion activity.
Rondo is relevant to defenders monitoring post-exploitation activity following newly disclosed RCE vulnerabilities, particularly where attackers rapidly weaponize public proof-of-concept material to compromise exposed services and convert them into mining and botnet infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We have previously published a blog on what organizations need to know about the actively exploited CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | We have observed a substantial rise in community-driven penetration testing that utilizes popular Nuclei templates including both valid and in-valid proof-of-concept exploits, alongside an increase in malware botnets leveraging CVE-2025-55182 like Mirai and Rondo.
This attack is associated with CVE-2024-36401, an X-Path expression evaluation issue in Geoserver. | So what we have is the "good old" Rondo botnet. It has been seen going after Geoserver before.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The first stage shell file has many names, but always in the pattern of rondo.XXX.sh where XXX is three alphabet characters... The contents of each are identical.
it removes any pre-existing “rondo” files... and then attempts to download malware of a specific platform type, and attempt to execute it... via the use of chained commands that try one command, then another, and then another, such as we can see here with the use of wget, then curl, then busybox.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware mentioned as leveraging CVE-2025-55182 in observed exploitation activity.
Rondo is described as a botnet delivered via a command executed through exploitation of GeoServer CVE-2024-36401, using wget/busybox/curl to fetch and run a remote shell script from 45.153.34.153.
A competing Linux malware/miner family referenced as a target of the framework’s anti-competition detection/termination logic.
A miner deployment chain using a shell script installer (rondo.aqu.sh) that pulls a propagation module plus a cryptocurrency mining component, delivered via exploitation of CVE-2025-55182.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.