RondoDox Botnet Expands to 174 Exploits, Leveraging Residential IP Infrastructure at Scale
ID: 29bb8be2-c3a1-5bed-b5f0-411864765c26
STIX ID: report--29bb8be2-c3a1-5bed-b5f0-411864765c26
Feed Name: cybersecurityNews.com
RondoDox is a Mirai-based botnet first observed in May 2025 that has grown into a large-scale DoS-focused campaign, performing up to 15,000 exploitation attempts per day and supporting 174 distinct exploits across 18 architectures. Researchers observed rapid adoption of newly disclosed CVEs (including pre-public exploitation), a shotgun exploitation approach that later narrowed to high-value targets, and use of compromised residential IPs to host malicious payloads—indicating a persistent, well-resourced operation that actively leverages a broad exploit set and deceptive hosting infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
