Researchers reported that the RondoDox botnet is actively exploiting CVE-2018-5999, a critical remote code execution flaw in Asus routers that lets unauthenticated attackers gain root access. VulnCheck said it observed in-the-wild exploitation beginning on May 17, marking the first known real-world abuse of the 2018 vulnerability even though public exploit code has been available for years. The flaw affects widely deployed consumer routers, with more than 1 million Asus devices believed to be exposed online.
RondoDox, a Linux-focused botnet first seen in mid-2025 and often described as a Mirai variant, uses multi-stage mass exploitation against end-of-life and IoT devices, frequently chaining older embedded-device CVEs before deploying malware and connecting to command-and-control infrastructure. Researchers said the botnet is primarily used for denial-of-service attacks and appears to rely on compromised residential IP addresses for hosting, suggesting its operators closely track vulnerability disclosures and rapidly weaponize older flaws in consumer networking gear.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On May 22, 2026, reporting disclosed that RondoDox was exploiting CVE-2018-5999 in Asus routers at scale. The coverage also highlighted the botnet's use of older embedded-device CVEs, compromised residential IPs, and likely monitoring of vulnerability disclosures to weaponize flaws quickly.
VulnCheck began observing in-the-wild exploitation of CVE-2018-5999 by the RondoDox botnet on May 17, 2026. Researchers said this was the first known active exploitation of the long-public Asus router vulnerability.
F5 Labs reported tracking the RondoDox threat actor since July 15, 2025 as it targeted IoT and other Linux-based devices using numerous command-injection and remote-code-execution exploits. The researchers documented its limited set of distribution IPs, rotating rondo.XXX.sh first-stage scripts, architecture-specific payloads, and indicators including the email address bang2012@tutanota.de.
Researchers first saw the Linux-focused RondoDox botnet in mid-2025. It was described as a Mirai variant that targets end-of-life and IoT devices using multi-stage exploitation.
Exploit code for CVE-2018-5999, a critical remote code execution flaw in Asus routers allowing unauthenticated root access, was publicly available in 2018. Despite this, no real-world exploitation had been reported for years.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcelinkedin.com
Open sourcef5.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.