Botnet Loader-as-a-Service Infrastructure Distributing RondoDoX and Mirai Payloads
ID: 92b800e4-d829-50ee-bf97-2410f3f7225e
STIX ID: report--92b800e4-d829-50ee-bf97-2410f3f7225e
Feed Name: CloudSEK Blog
CloudSEK uncovered a six-month loader-as-a-service botnet operation (RondoDoX / Morte / Mirai) that systematically exploits unsanitized web GUI fields, default credentials and known CVEs (WebLogic, WordPress, vBulletin, etc.) to achieve remote code execution on SOHO routers, embedded Linux devices and enterprise apps; operators deliver staged droppers and native payloads (cryptominers, Morte binaries), with extensive IOCs, impact analysis and prioritized remediation guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
