logo

RondoDox Botnet Expands to 174 Exploits, Leveraging Residential IP Infrastructure at Scale

ID: 29bb8be2-c3a1-5bed-b5f0-411864765c26

STIX ID: report--29bb8be2-c3a1-5bed-b5f0-411864765c26

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

RondoDox is a Mirai-based botnet first observed in May 2025 that has grown into a large-scale DoS-focused campaign, performing up to 15,000 exploitation attempts per day and supporting 174 distinct exploits across 18 architectures. Researchers observed rapid adoption of newly disclosed CVEs (including pre-public exploitation), a shotgun exploitation approach that later narrowed to high-value targets, and use of compromised residential IPs to host malicious payloads—indicating a persistent, well-resourced operation that actively leverages a broad exploit set and deceptive hosting infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.