RondoDox botnet expands arsenal targeting 174 flaws, and hits 15,000 daily exploit attempts
ID: 5d7b5a0e-8036-50f1-9db9-c3fa219026b1
STIX ID: report--5d7b5a0e-8036-50f1-9db9-c3fa219026b1
Feed Name: Security Affairs
RondoDox, a botnet active since 2024, ramped up a focused campaign between May 2025 and February 2026 targeting 174 vulnerabilities (148 mapped CVEs) with as many as 15,000 daily exploit attempts; researchers observed rapid adoption of new public PoCs (including React2Shell/CVE-2025-55182), waves of broad testing followed by consolidation on high-value exploits, inconsistent exploit implementations, and payload deployment such as cryptominers, while BitSight cautioned against misattributed findings about alleged loader-as-a-service or P2P C2 claims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
