RondoDox Botnet Scales Up, Exploiting 174 Vulnerabilities via Residential IPs
ID: 6a6ba523-32a7-59a1-a756-0b0b86b5af57
STIX ID: report--6a6ba523-32a7-59a1-a756-0b0b86b5af57
Feed Name: GBHackers
Threat Score
RondoDox is a rapidly evolving Mirai‑style botnet and automated exploitation engine that has weaponized 174 vulnerabilities (≈148 CVEs plus public POCs) to compromise internet‑exposed devices, repurpose residential IPs for hosting, deploy an XMRig miner, and provide a DDoS/initial‑access platform; operators separate noisy exploitation infrastructure from a small, stealthy C2 footprint and aggressively adopt newly disclosed (and sometimes pre‑publication) bugs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
