Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

RondoDox

175
Global rank
189 infographic chevron month
Month rank
184 infographic chevron week
Week rank
0
IOCs

RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.

Botnet
Type
Unknown
Origin
1 June, 2025
First seen
18 May, 2026
Last seen

How to analyze RondoDox with ANY.RUN

Type
Unknown
Origin
1 June, 2025
First seen
18 May, 2026
Last seen

IOCs

IP addresses
74.194.191.52
88.221.169.152
23.216.77.28
48.192.1.64
150.171.28.11
142.251.20.132
20.31.169.57
150.171.22.17
57.153.246.3
150.171.109.193
150.171.27.11
150.171.109.194
92.123.104.33
142.251.110.95
74.178.240.61
23.52.181.141
20.190.160.2
104.18.22.222
48.209.6.48
23.52.181.212
Hashes
b16142f0c436ae52995dc762d6961bae40806e0f9169bbaa6140292a0806edc5
4c141f368da1152af24808794c501b65be66f1550e1b0b2f6c10578fb945eaf2
caa3d73a4067cf98ff271cc9ce5c826f7dadf8afe4df67be2330133f872c73e8
33c754a7a1db91f9a6f96beb98de666930f62b88704d4804517b931d8993760f
7fe93b1b87f935e01ab44d6ca503762ec1d41c15e31f2d3b4a86d6a961301890
b996c947dc5d69a68edcfcd03dea7a15b2e8fb62eef3238fe6bc505d12a6ad01
8232c450f967d7f2f22c54582f0667f4c033ae62e6d450ff8a35c47486249443
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
f51a7acfffec56d6751561966d947d3fd199b74528c07dabdcf5fcb33d5b2e85
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
Domains
api.edgeoffer.microsoft.com
xpaywalletcdn.azureedge.net
nexusrules.officeapps.live.com
www.bing.com
slscr.update.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
config.edge.skype.com
login.live.com
copilot.microsoft.com
activation-v2.sls.microsoft.com
edge-mobile-static.azureedge.net
edge.microsoft.com
www.googleapis.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
edgeassetservice.azureedge.net
edge-cloud-resource-static.azureedge.net
crl.microsoft.com
edge-consumer-static.azureedge.net
google.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:-j-fhytd8o1luytfzffu9kli-giwmatbov1ytkizcfq&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766135237&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
http://74.194.191.52/rondo.mips
http://74.194.191.52/favicon.ico
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=67&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1779147726&lafgdate=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d151%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://update.googleapis.com/service/update2/json?cup2key=14:5xgvtowkgpq20-pzfqqyp1ptpv7vrp2m2rxyrb1ohww&cup2hreq=a3a692484f6c945420bc182260b0bf98b6dba09e770f8152d57423288fca41e1
https://clients2.googleusercontent.com/crx/blobs/axjdbcb3bcsv6gp8gpeje3rcgnj3eqijk3zarzrmzgm66kmi_kixwkoupj_h1mukewkz3sgh3wqx91p8sppzyc4bmn9mhbflnecjueea0ppdyi6pgavem-afggz7z7d2-5eaxlka5zzbahtzgxeunigzgslrk_1yzgwg/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_104_1_0.crx
https://edgeassetservice.azureedge.net/assets/domains_config_gz/3.0.12/asset?assetgroup=entityextractiondomainsconfig
https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.11.81/asset?assetgroup=shoreline
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

RondoDox: The Exploit-Shotgun Botnet Infecting Routers and DVRs

Key Takeaways

  1. RondoDox exploits a wide mix of publicly known CVEs and default credentials to build a diverse botnet.
  2. Primary targets are internet-exposed routers, DVRs/NVRs, CCTV devices and unpatched web apps — often forgotten in asset inventories.
  3. IoT to Enterprise Pivot: From DVRs to WebLogic servers, v2's 650% exploit surge demands zero-trust for all edges.
  4. Prevention priorities: patching, removing unsupported devices, replacing default passwords, and isolating IoT/CCTV networks.
  5. Detection is faster when you combine network telemetry (egress anomalies, C2 beacons) with host artifacts (unexpected binaries, cronjobs).
  6. Traffic mimicry (e.g., Fortnite floods) blends attacks: deploy DPI and anomaly detection early. Multilayer hooks like crontabs survive reboots: hunt renamed binaries and rogue scripts routinely.
  7. Loader-as-a-Service Risk: Bundling with Mirai amplifies spread—block dynamic downloads via URL filtering
  8. ANY.RUN’s Threat Intelligence Lookup speeds incident response by quickly enriching hashes/domains/CVEs and helping prioritize remediation. Use it to map RondoDox indicators to actionable patches and blocks.

destinationIP:"2.16.253.157"

IP detected as RondoDox IOC via TI Lookup IP found in RondoDox malware samples via TI Lookup

  1. Malware sandboxes like ANY.RUN detonate RondoDox samples in isolated VMs, revealing behaviors like persistence scripts or C2 drops without risking production, safely decoding XOR payloads for IOC extraction. They simulate multi-arch environments to trace loader chains, accelerating reverse engineering. Interactive sandboxes can reveal C2 domains, beacon intervals, and secondary payloads to inform blocking/monitoring actions.

View analysis

RondoDox sample in the Sandbox RondoDox sample detonated in the ANY.RUN Sandbox

What is RondoDox Malware?

RondoDox represents a new generation of botnet malware characterized by its modular design, cross-platform capabilities, and aggressive exploitation tactics. The malware operates primarily on Linux-based systems and supports multiple architectures which allows RondoDox to infect a diverse range of devices, from consumer-grade routers to enterprise web servers.

The malware's core is a multi-stage dropper that ignores termination signals, probes writable directories, and deploys obfuscated binaries to evade static analysis. Once entrenched, it impersonates legitimate traffic mimicking games like Fortnite or VPN protocols like OpenVPN to mask C2 communications and DDoS floods.

A November 2025 variant, RondoDox v2, escalated with 75 exploits, including enterprise targets like WebLogic servers, signaling a shift from opportunistic IoT hits to strategic business compromises. This adaptability, coupled with rapid infrastructure rotation, has fueled a 230% surge in attacks from July to August 2025, per CloudSEK telemetry

RondoDox employs XOR obfuscation using the hexadecimal key 0x21 to encode its configuration data, including file paths, tool filenames, and command-and-control (C2) server addresses. This simple yet effective encoding mechanism helps RondoDox evade basic security analysis while maintaining operational efficiency. Recent variants have evolved to function as a "loader-as-a-service," co-packaging RondoDox with notorious malware families like Mirai and Morte, significantly complicating detection and remediation efforts.

What distinguishes RondoDox from earlier botnets is its systematic approach to persistence and stealth. The malware modifies system startup files, creates symbolic links, establishes cron jobs, and even renames critical system binaries like iptables, firewall utilities, and shutdown commands to random character strings. This deliberate sabotage of system recovery tools makes remediation exceptionally difficult once a device is compromised.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

RondoDox Malware Victimology

The campaign has been observed globally since mid-2025, with significant activity detected across North America, Europe, and Asia. Devices from over 30 vendors are vulnerable, including popular brands like TP-Link, D-Link, Cisco, Netgear, Linksys, Zyxel, QNAP, Tenda, and TOTOLINK. Organizations operating internet-facing network devices are at heightened risk, particularly those using equipment from vendors with inconsistent security update policies.

Primary targets include:

  • Small and medium-sized businesses operating retail stores, warehouses, and small offices with unmanaged security cameras, DVRs, and routers;
  • Internet service providers and hosting companies with exposed network infrastructure;
  • Home users with consumer-grade routers and IoT devices running outdated firmware;
  • Educational institutions with legacy network equipment and security systems;
  • Healthcare facilities using networked security cameras and monitoring systems;
  • Enterprise organizations with vulnerable network edge devices, particularly those maintaining legacy systems or delayed patching schedules.

How RondoDox Functions

RondoDox spreads using two complementary vectors:

  • Exploit shotgun: automated probes that attempt many publicly disclosed vulnerabilities (some originally disclosed at security contests) across routers, DVRs, CCTV devices and web apps. Any unpatched service with a known remote code execution or command injection flaw is a target.
  • Credential abuse & weak defaults: many IoT/edge devices still use default factory credentials or weak passwords; RondoDox includes simple credential-guessing routines to gain access.

Once a device is compromised the loader often drops multi-architecture binaries and may attempt to scan local subnets to find adjacent vulnerable devices, accelerating lateral spread in poorly segmented environments.

Initial entry leverages command injection in exposed interfaces: unsanitized POSTs (e.g., NTP/hostname fields) execute wget/curl | sh chains downloading rondo..sh. Vectors include CVE-2023-1389 (TP-Link routers), CVE-2024-3721 (TBK DVRs), and weak creds like root/123456. The script probes mounts without noexec, drops payloads to /tmp/lib, and clears history.

Spread occurs via botnet scanning: infected nodes probe ports 22/23/80/443 for vulns, chaining to Mirai for brute-force amplification. Loader-as-a-service rotates C2s (e.g., 74[.]194[.]191[.]52), enabling horizontal infection across networks.

RondoDox operates as a modular ELF binary with embedded shell scripts, decoding configs via XOR (key 0x21) to reveal C2 IPs and paths. Post-decryption, it forks processes for anti-analysis (killing debuggers), persistence setup, and C2 beaconing over port 345 or HTTP. Command handlers parse base64-encoded directives for floods or downloads, forging packets with magic bytes (e.g., OpenVPN's \x38) for evasion. The v2 variant adds self-healing: if removed, cron jobs redownload from loaders like rondo.dtm.sh. Multi-arch support ensures cross-device functionality, with traffic blending via protocol mimicry.

Sandbox Analysis of a RondoDox Sample

ANY.RUN’s Interactive Sandbox provides isolated, instrumented environments where security researchers and analysts can safely execute suspicious files without risking production systems. For RondoDox analysis, sandboxes enable:

  • Behavioral observation: Watching RondoDox's complete execution flow from initial startup through persistence establishment, C2 communication, and attack preparation.

  • Network traffic capture: Recording all network connections, payload downloads, and C2 communications to identify infrastructure and attack patterns.

  • System modification tracking: Monitoring file system changes, process creation, registry/configuration modifications, and symbolic link creation.

  • Evasion technique identification: Detecting anti-sandbox measures such as the malware's monitoring for SIGKILL (exit code 137) and virtualization environment checks.

View a RondoDox sample analysis

RondoDox Sandbox analysis RondoDox detonated in the Interactive Sandbox

An analyst could focus on the loader used to deliver the botnet’s main binary, since the loader is the component that creates the largest number of artifacts.

The first important element of the script is the check: [ -t 0 ] && exit 0 This ensures the script exits if standard input is connected to a terminal, meaning it is intended for background or automated execution, not interactive use.

The core logic begins with a loop through all running processes. For each PID, the script checks for the presence of the exe file. If it is missing, the script terminates the process with kill -9. Then it retrieves the symlink to the executable file and skips processes whose path contains /lib. For all others, it checks whether their paths contain certain directories (tmp, var, dev, mnt, run, home), and if a match is found, it kills the process.

Next, the script attempts to disable security mechanisms: it deactivates SELinux and stops AppArmor. It then remounts the root filesystem in read-write mode, allowing modification of system files. After that, it deletes the contents of /var/cache/* and ~/.cache, clearing system and user caches.

Malware remounts the file system Malware remounts the file system

The script then moves to /dev and deletes files whose names correspond to different processor architectures, such as arc, arm, arm4, etc. This process is repeated for multiple directories. This approach ensures the removal of potential artifacts or competing binaries.

Then follows a series of blocks for downloading and running binaries named rondo for different architectures, while also setting execution permissions. All existing rondo processes are then killed, and ./rondo "bash.mips" is executed. The check

[ $? -eq 137 ] && exit 0

verifies whether the exit code is 137, and if so, the script exits. This pattern is repeated for many architectures, allowing the script to try running the appropriate binary for the current system and exit upon successful execution.

RondoDox process sequence RondoDox process sequence script establishing persistence

At the end, history -c clears the shell command history, and exit 0 terminates the script successfully.

The overall mechanism includes self-cleaning, disabling protections, removing competitors, and deploying a payload tailored to the system’s architecture.

RondoDox demonstrates a typical modern botnet infection and persistence strategy: aggressive system cleanup from competitors (including cryptominers), disabling security mechanisms, and adaptation to a wide range of architectures. This makes it dangerous for vulnerable Linux systems, IoT devices, and servers, where it can be used to conduct powerful DDoS attacks, masking its traffic as legitimate services.

What RondoDox can do to an endpoint device

On compromised endpoints RondoDox has been observed to:

  • Install a lightweight loader/agent that persists and executes commands from a C2.
  • Participate in distributed denial-of-service (DDoS) campaigns.
  • Provide proxy/residential-proxy services by relaying traffic.
  • Download and execute secondary payloads (cryptominers, additional botnet modules, or commodity malware families).
  • Hide or obfuscate network traffic to blend with legitimate services (some variants mimic game/Discord/VPN traffic patterns).

The malware typically focuses on leveraging the compromised device’s network capacity rather than stealing local user documents — though lateral movement and pivoting into adjacent networks are possible if the environment is misconfigured.

Examples of the most successful RondoDox attacks

  • June 15, 2025 TP-Link Exploitation: First documented hit via CVE-2023-1389 on Archer AX21 routers, enabling mass shell access and botnet enlistment for UDP floods; affected thousands in consumer networks.

  • July 2025 TBK DVR Campaign: Leveraged CVE-2024-3721 to compromise retail surveillance systems, leading to DDoS against e-commerce targets; Fortinet linked it to renamed binaries hindering recovery.

  • September 2025 Loader Surge: 230% attack spike via Mirai bundling, hitting SOHO routers for cryptomining; CloudSEK reported global IoT infections.

  • November 2025 XWiki Pivot: v2 exploited CVE-2025-24893 for code execution on unpatched wikis, pulling enterprise servers into the botnet; early adopter status amplified spread.

  • October 2025 Enterprise Escalation: 75-vector assault on WebLogic/QNAP via honeypots, with User-Agent signatures like bang2013@atomicmail[.]io; targeted manufacturing OT for proxying.

Gathering Threat Intelligence on RondoDox Malware

Threat intelligence services provide IOC that can be integrated into security tools:

  • IPs: Block connections to/from known RondoDox C2 servers;

  • Domains: Prevent DNS resolution of malicious infrastructure;

  • File hashes: Identify RondoDox binaries through endpoint scanning;

  • URLs: Block access to payload download locations.

Use Threat Intelligence Lookup to check suspicious artifacts and analyze the malware’s behavior via safe sandbox detonations. Get contextual data to understand threat actor motivations, capabilities, and typical targets to assess your risk profile

Start exploring the threat by looking it up by the name:

threatName:"rondodox"

RondoDox samples found via TI Lookup RondoDox sample sandbox analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

RondoDox is a cautionary example of modern botnet evolution: modular, multi-architecture, and opportunistic, weaponizing old and new CVEs while blending credential abuse into its playbook. The most effective defenses are not purely signature-based: they are a combination of up-to-date patching, rigorous asset management, network segmentation, strict management plane controls, centralized telemetry, and a robust program for threat intelligence and sandbox-backed analysis. Organizations that treat edge devices as first-class security assets will reduce their exposure to RondoDox and similar campaigns

Trial TI Lookup to start gathering actionable threat intelligence on RondoDox: just sign up to ANY.RUN.

HAVE A LOOK AT

Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More