Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

RondoDox

187
Global rank
194 infographic chevron month
Month rank
185 infographic chevron week
Week rank

RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.

Botnet
Type
Unknown
Origin
1 June, 2025
First seen
7 August, 2026
Last seen

How to analyze RondoDox with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
7 August, 2026
Last seen

IOCs

IP addresses
18.172.112.119
194.26.192.87
45.153.34.46
91.189.91.96
185.125.190.58
185.125.190.57
141.98.10.168
91.189.91.157
185.125.190.56
91.189.91.98
185.125.190.100
54.192.100.80
45.125.66.100
185.125.188.60
74.194.191.52
88.221.169.152
23.216.77.28
48.192.1.64
150.171.28.11
142.251.20.132
Hashes
ec1ce89d9080a71619e3b17c7906f677d3563e87ee317b4e9e73e3ab4163b5b2
4dc02f52216eee33e946e81e21860f951e2f5d47b54a7615209b02071ce3480c
4377e894b3e7956b74d467118164b7023e9b0f0f4c151e464d00991e30f924ac
9a243939f62374eabd5f170bddc4cb2bf9c027c608edfefdbe9c995130c5c51a
f9120c06aad5aa4add1b646456199fd34b4fa72c6eb8ba4d37d85a59d7cac478
c188eae53f0599d10de6992b70a293b65b84872ebab3c441a8e122062c6c780e
cb02a5f521838b47c1e1f3e3f2acdf62b42c2fb33de28c7341ae7cc25e9c045c
247e9cc5835d51e992f4b429549f228df111b31b388ae0d01b18539ec045de0a
ba6c9251473f21a254a92e991cdbe649d3eb0b2d35028a184166af062398b0a1
1342ef186c9b3c46e468b3d1c8e514d5698acb9be337cd827da738d874581f96
fd4c9fda9cd3f9ae7c962b0ddf37232294d55580e1aa165aa06129b8549389eb
b16e15764b8bc06c5c3f9f19bc8b99fa48e7894aa5a6ccdad65da49bbf564793
9511ac1a00c40e879a726eed9a549adc725faff959b218011d3ed1c66f478674
86b0c5a1e2b73b08fd54c727f4458649ed9fe3ad1b6e8ac9460c070113509a1e
a1f2a051de986301a710ebbee1a385bfb84b414c65e110e3dd6c21b5538e12e7
5279f80f139fcf962ac44abc4b79b67d14807c8f5a6d9ec8e9e3f7023532961d
64c84fb0a53f2d505eec9a97e93d122260f0b6a68686ad76eba37b57d5c427c5
a49fb5c899cd69337dd9fd4d6808cb25dd27c81e90869ed817f2873c1275a526
988566fdb7f3324d33802fcec29676cb0e964dc4c162634b3033bc3d3bd5107d
32f9af87b3564b8e8126c44b30074cc3f2a148ee57c4f43eced5a1a492ec2992
Domains
ntp.ubuntu.com
google.com
connectivity-check.ubuntu.com
www.safebrowse.io
block.charter-prod.hosted.cujo.io
api.snapcraft.io
api.edgeoffer.microsoft.com
xpaywalletcdn.azureedge.net
nexusrules.officeapps.live.com
www.bing.com
slscr.update.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
config.edge.skype.com
login.live.com
copilot.microsoft.com
activation-v2.sls.microsoft.com
edge-mobile-static.azureedge.net
edge.microsoft.com
www.googleapis.com
settings-win.data.microsoft.com
URLs
http://connectivity-check.ubuntu.com/
http://194.26.192.87/rondo.vcp.sh
https://block.charter-prod.hosted.cujo.io/warn.html?url=http://194.26.192.87/rondo.vcp.sh&token=4938fb75
http://194.26.192.87/rondo.8.jpg
http://194.26.192.87/rondo.9.jpg
http://194.26.192.87/rondo.10.jpg
http://194.26.192.87/rondo.7.jpg
http://194.26.192.87/rondo.1.jpg
http://194.26.192.87/softirq.x86_64
http://194.26.192.87/rondo.tpp.sh
http://194.26.192.87/rondo.qpu.sh
http://194.26.192.87/rondo.lol
http://194.26.192.87/rondo.u.sh
https://www.safebrowse.io/warn.html?url=http://194.26.192.87/rondo.lol&token=23b20625
http://194.26.192.87/rondo.5.jpg
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:-j-fhytd8o1luytfzffu9kli-giwmatbov1ytkizcfq&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1024
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2815
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10289
comments 0

RondoDox: The Exploit-Shotgun Botnet Infecting Routers and DVRs

Key Takeaways

  1. RondoDox exploits a wide mix of publicly known CVEs and default credentials to build a diverse botnet.
  2. Primary targets are internet-exposed routers, DVRs/NVRs, CCTV devices and unpatched web apps — often forgotten in asset inventories.
  3. IoT to Enterprise Pivot: From DVRs to WebLogic servers, v2's 650% exploit surge demands zero-trust for all edges.
  4. Prevention priorities: patching, removing unsupported devices, replacing default passwords, and isolating IoT/CCTV networks.
  5. Detection is faster when you combine network telemetry (egress anomalies, C2 beacons) with host artifacts (unexpected binaries, cronjobs).
  6. Traffic mimicry (e.g., Fortnite floods) blends attacks: deploy DPI and anomaly detection early. Multilayer hooks like crontabs survive reboots: hunt renamed binaries and rogue scripts routinely.
  7. Loader-as-a-Service Risk: Bundling with Mirai amplifies spread—block dynamic downloads via URL filtering
  8. ANY.RUN’s Threat Intelligence Lookup speeds incident response by quickly enriching hashes/domains/CVEs and helping prioritize remediation. Use it to map RondoDox indicators to actionable patches and blocks.

destinationIP:"2.16.253.157"

IP detected as RondoDox IOC via TI Lookup IP found in RondoDox malware samples via TI Lookup

  1. Malware sandboxes like ANY.RUN detonate RondoDox samples in isolated VMs, revealing behaviors like persistence scripts or C2 drops without risking production, safely decoding XOR payloads for IOC extraction. They simulate multi-arch environments to trace loader chains, accelerating reverse engineering. Interactive sandboxes can reveal C2 domains, beacon intervals, and secondary payloads to inform blocking/monitoring actions.

View analysis

RondoDox sample in the Sandbox RondoDox sample detonated in the ANY.RUN Sandbox

What is RondoDox Malware?

RondoDox represents a new generation of botnet malware characterized by its modular design, cross-platform capabilities, and aggressive exploitation tactics. The malware operates primarily on Linux-based systems and supports multiple architectures which allows RondoDox to infect a diverse range of devices, from consumer-grade routers to enterprise web servers.

The malware's core is a multi-stage dropper that ignores termination signals, probes writable directories, and deploys obfuscated binaries to evade static analysis. Once entrenched, it impersonates legitimate traffic mimicking games like Fortnite or VPN protocols like OpenVPN to mask C2 communications and DDoS floods.

A November 2025 variant, RondoDox v2, escalated with 75 exploits, including enterprise targets like WebLogic servers, signaling a shift from opportunistic IoT hits to strategic business compromises. This adaptability, coupled with rapid infrastructure rotation, has fueled a 230% surge in attacks from July to August 2025, per CloudSEK telemetry

RondoDox employs XOR obfuscation using the hexadecimal key 0x21 to encode its configuration data, including file paths, tool filenames, and command-and-control (C2) server addresses. This simple yet effective encoding mechanism helps RondoDox evade basic security analysis while maintaining operational efficiency. Recent variants have evolved to function as a "loader-as-a-service," co-packaging RondoDox with notorious malware families like Mirai and Morte, significantly complicating detection and remediation efforts.

What distinguishes RondoDox from earlier botnets is its systematic approach to persistence and stealth. The malware modifies system startup files, creates symbolic links, establishes cron jobs, and even renames critical system binaries like iptables, firewall utilities, and shutdown commands to random character strings. This deliberate sabotage of system recovery tools makes remediation exceptionally difficult once a device is compromised.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

RondoDox Malware Victimology

The campaign has been observed globally since mid-2025, with significant activity detected across North America, Europe, and Asia. Devices from over 30 vendors are vulnerable, including popular brands like TP-Link, D-Link, Cisco, Netgear, Linksys, Zyxel, QNAP, Tenda, and TOTOLINK. Organizations operating internet-facing network devices are at heightened risk, particularly those using equipment from vendors with inconsistent security update policies.

Primary targets include:

  • Small and medium-sized businesses operating retail stores, warehouses, and small offices with unmanaged security cameras, DVRs, and routers;
  • Internet service providers and hosting companies with exposed network infrastructure;
  • Home users with consumer-grade routers and IoT devices running outdated firmware;
  • Educational institutions with legacy network equipment and security systems;
  • Healthcare facilities using networked security cameras and monitoring systems;
  • Enterprise organizations with vulnerable network edge devices, particularly those maintaining legacy systems or delayed patching schedules.

How RondoDox Functions

RondoDox spreads using two complementary vectors:

  • Exploit shotgun: automated probes that attempt many publicly disclosed vulnerabilities (some originally disclosed at security contests) across routers, DVRs, CCTV devices and web apps. Any unpatched service with a known remote code execution or command injection flaw is a target.
  • Credential abuse & weak defaults: many IoT/edge devices still use default factory credentials or weak passwords; RondoDox includes simple credential-guessing routines to gain access.

Once a device is compromised the loader often drops multi-architecture binaries and may attempt to scan local subnets to find adjacent vulnerable devices, accelerating lateral spread in poorly segmented environments.

Initial entry leverages command injection in exposed interfaces: unsanitized POSTs (e.g., NTP/hostname fields) execute wget/curl | sh chains downloading rondo..sh. Vectors include CVE-2023-1389 (TP-Link routers), CVE-2024-3721 (TBK DVRs), and weak creds like root/123456. The script probes mounts without noexec, drops payloads to /tmp/lib, and clears history.

Spread occurs via botnet scanning: infected nodes probe ports 22/23/80/443 for vulns, chaining to Mirai for brute-force amplification. Loader-as-a-service rotates C2s (e.g., 74[.]194[.]191[.]52), enabling horizontal infection across networks.

RondoDox operates as a modular ELF binary with embedded shell scripts, decoding configs via XOR (key 0x21) to reveal C2 IPs and paths. Post-decryption, it forks processes for anti-analysis (killing debuggers), persistence setup, and C2 beaconing over port 345 or HTTP. Command handlers parse base64-encoded directives for floods or downloads, forging packets with magic bytes (e.g., OpenVPN's \x38) for evasion. The v2 variant adds self-healing: if removed, cron jobs redownload from loaders like rondo.dtm.sh. Multi-arch support ensures cross-device functionality, with traffic blending via protocol mimicry.

Sandbox Analysis of a RondoDox Sample

ANY.RUN’s Interactive Sandbox provides isolated, instrumented environments where security researchers and analysts can safely execute suspicious files without risking production systems. For RondoDox analysis, sandboxes enable:

  • Behavioral observation: Watching RondoDox's complete execution flow from initial startup through persistence establishment, C2 communication, and attack preparation.

  • Network traffic capture: Recording all network connections, payload downloads, and C2 communications to identify infrastructure and attack patterns.

  • System modification tracking: Monitoring file system changes, process creation, registry/configuration modifications, and symbolic link creation.

  • Evasion technique identification: Detecting anti-sandbox measures such as the malware's monitoring for SIGKILL (exit code 137) and virtualization environment checks.

View a RondoDox sample analysis

RondoDox Sandbox analysis RondoDox detonated in the Interactive Sandbox

An analyst could focus on the loader used to deliver the botnet’s main binary, since the loader is the component that creates the largest number of artifacts.

The first important element of the script is the check: [ -t 0 ] && exit 0 This ensures the script exits if standard input is connected to a terminal, meaning it is intended for background or automated execution, not interactive use.

The core logic begins with a loop through all running processes. For each PID, the script checks for the presence of the exe file. If it is missing, the script terminates the process with kill -9. Then it retrieves the symlink to the executable file and skips processes whose path contains /lib. For all others, it checks whether their paths contain certain directories (tmp, var, dev, mnt, run, home), and if a match is found, it kills the process.

Next, the script attempts to disable security mechanisms: it deactivates SELinux and stops AppArmor. It then remounts the root filesystem in read-write mode, allowing modification of system files. After that, it deletes the contents of /var/cache/* and ~/.cache, clearing system and user caches.

Malware remounts the file system Malware remounts the file system

The script then moves to /dev and deletes files whose names correspond to different processor architectures, such as arc, arm, arm4, etc. This process is repeated for multiple directories. This approach ensures the removal of potential artifacts or competing binaries.

Then follows a series of blocks for downloading and running binaries named rondo for different architectures, while also setting execution permissions. All existing rondo processes are then killed, and ./rondo "bash.mips" is executed. The check

[ $? -eq 137 ] && exit 0

verifies whether the exit code is 137, and if so, the script exits. This pattern is repeated for many architectures, allowing the script to try running the appropriate binary for the current system and exit upon successful execution.

RondoDox process sequence RondoDox process sequence script establishing persistence

At the end, history -c clears the shell command history, and exit 0 terminates the script successfully.

The overall mechanism includes self-cleaning, disabling protections, removing competitors, and deploying a payload tailored to the system’s architecture.

RondoDox demonstrates a typical modern botnet infection and persistence strategy: aggressive system cleanup from competitors (including cryptominers), disabling security mechanisms, and adaptation to a wide range of architectures. This makes it dangerous for vulnerable Linux systems, IoT devices, and servers, where it can be used to conduct powerful DDoS attacks, masking its traffic as legitimate services.

What RondoDox can do to an endpoint device

On compromised endpoints RondoDox has been observed to:

  • Install a lightweight loader/agent that persists and executes commands from a C2.
  • Participate in distributed denial-of-service (DDoS) campaigns.
  • Provide proxy/residential-proxy services by relaying traffic.
  • Download and execute secondary payloads (cryptominers, additional botnet modules, or commodity malware families).
  • Hide or obfuscate network traffic to blend with legitimate services (some variants mimic game/Discord/VPN traffic patterns).

The malware typically focuses on leveraging the compromised device’s network capacity rather than stealing local user documents — though lateral movement and pivoting into adjacent networks are possible if the environment is misconfigured.

Examples of the most successful RondoDox attacks

  • June 15, 2025 TP-Link Exploitation: First documented hit via CVE-2023-1389 on Archer AX21 routers, enabling mass shell access and botnet enlistment for UDP floods; affected thousands in consumer networks.

  • July 2025 TBK DVR Campaign: Leveraged CVE-2024-3721 to compromise retail surveillance systems, leading to DDoS against e-commerce targets; Fortinet linked it to renamed binaries hindering recovery.

  • September 2025 Loader Surge: 230% attack spike via Mirai bundling, hitting SOHO routers for cryptomining; CloudSEK reported global IoT infections.

  • November 2025 XWiki Pivot: v2 exploited CVE-2025-24893 for code execution on unpatched wikis, pulling enterprise servers into the botnet; early adopter status amplified spread.

  • October 2025 Enterprise Escalation: 75-vector assault on WebLogic/QNAP via honeypots, with User-Agent signatures like bang2013@atomicmail[.]io; targeted manufacturing OT for proxying.

Gathering Threat Intelligence on RondoDox Malware

Threat intelligence services provide IOC that can be integrated into security tools:

  • IPs: Block connections to/from known RondoDox C2 servers;

  • Domains: Prevent DNS resolution of malicious infrastructure;

  • File hashes: Identify RondoDox binaries through endpoint scanning;

  • URLs: Block access to payload download locations.

Use Threat Intelligence Lookup to check suspicious artifacts and analyze the malware’s behavior via safe sandbox detonations. Get contextual data to understand threat actor motivations, capabilities, and typical targets to assess your risk profile

Start exploring the threat by looking it up by the name:

threatName:"rondodox"

RondoDox samples found via TI Lookup RondoDox sample sandbox analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

RondoDox is a cautionary example of modern botnet evolution: modular, multi-architecture, and opportunistic, weaponizing old and new CVEs while blending credential abuse into its playbook. The most effective defenses are not purely signature-based: they are a combination of up-to-date patching, rigorous asset management, network segmentation, strict management plane controls, centralized telemetry, and a robust program for threat intelligence and sandbox-backed analysis. Organizations that treat edge devices as first-class security assets will reduce their exposure to RondoDox and similar campaigns

Trial TI Lookup to start gathering actionable threat intelligence on RondoDox: just sign up to ANY.RUN.

HAVE A LOOK AT

LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
ClickFix screenshot
ClickFix is a sophisticated social engineering technique that tricks users into manually executing malicious commands on their devices. It masquerades as a "quick fix" for fake technical issues, CAPTCHA verifications, or error messages, often hijacking the clipboard to paste harmful PowerShell or terminal commands. This user-assisted approach helps it bypass traditional security controls, leading to infostealers like Lumma Stealer, RATs, and other malware.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More
DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More