logo

Botnet Loader-as-a-Service Infrastructure Distributing RondoDoX and Mirai Payloads

ID: 92b800e4-d829-50ee-bf97-2410f3f7225e

STIX ID: report--92b800e4-d829-50ee-bf97-2410f3f7225e

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2025-09-25

Date Updated: 2026-07-20

...
...

CloudSEK uncovered a six-month loader-as-a-service botnet operation (RondoDoX / Morte / Mirai) that systematically exploits unsanitized web GUI fields, default credentials and known CVEs (WebLogic, WordPress, vBulletin, etc.) to achieve remote code execution on SOHO routers, embedded Linux devices and enterprise apps; operators deliver staged droppers and native payloads (cryptominers, Morte binaries), with extensive IOCs, impact analysis and prioritized remediation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.