RondoDox Botnet Expands Its Reach: A Growing Threat to Global Network Infrastructure

Listen to this Post

Featured Image
The digital world faces a growing menace as the RondoDox botnet intensifies its operations, exploiting vulnerabilities across a wide array of devices worldwide. Cybersecurity experts are raising alarms over its aggressive tactics, targeting internet-exposed infrastructure with a precision and scale that suggest a new era of automated cyberattacks. From routers to DVRs and IoT devices, no networked device appears safe as RondoDox broadens its reach, leveraging old and new exploits to build a vast army of compromised devices for malicious purposes.

RondoDox’s Aggressive Expansion and Tactics

Malware campaigns distributing the RondoDox botnet have recently expanded their targeting to exploit over 50 vulnerabilities across more than 30 vendors. Trend Micro characterizes this as an “exploit shotgun” approach, where attackers indiscriminately target routers, digital video recorders (DVRs), network video recorders (NVRs), CCTV systems, web servers, and other network-connected devices.

The company reported a RondoDox intrusion attempt on June 15, 2025, exploiting CVE-2023-1389, a flaw in TP-Link Archer routers actively targeted since late 2022. Initially documented by Fortinet FortiGuard Labs in July 2025, RondoDox attacks focused on TBK DVRs and Four-Faith routers to assemble botnets capable of carrying out distributed denial-of-service (DDoS) attacks via HTTP, UDP, and TCP protocols.

Recent developments show RondoDox leveraging a “loader-as-a-service” infrastructure, packaging itself with Mirai and Morte payloads. This combined distribution increases its stealth and complicates detection and remediation efforts. The botnet now exploits 56 vulnerabilities, including 18 without CVE identifiers, spanning vendors such as D-Link, NETGEAR, Linksys, Cisco, QNAP, Apache, and dozens more.

Trend Micro describes this evolution as moving beyond opportunistic single-device attacks toward a multivector operation, signaling a significant advancement in automated network exploitation. CloudSEK has also observed large-scale loader-as-a-Service campaigns distributing RondoDox alongside Mirai and Morte via SOHO routers, IoT devices, and enterprise applications, targeting weak credentials, unsanitized inputs, and outdated CVEs.

Meanwhile, cybersecurity journalist Brian Krebs highlights the AISURU DDoS botnet, which sources much of its power from compromised IoT devices on U.S. internet providers such as AT&T, Comcast, and Verizon. AISURU, controlled in part by an operator allegedly based in Sao Paulo, Brazil, has grown to command an estimated 300,000 compromised hosts globally, making it one of the largest and most disruptive botnets today.

Adding to the complexity, GreyNoise reports coordinated botnet activity involving over 100,000 unique IPs from at least 100 countries, targeting U.S. Remote Desktop Protocol (RDP) services since October 8, 2025. Attack vectors include RD Web Access timing attacks and RDP web client login enumeration, with the majority of participating IPs sharing TCP fingerprints indicative of centralized control. Major sources of this traffic include Brazil, Argentina, Iran, China, Mexico, Russia, South Africa, and Ecuador.

What Undercode Say:

The RondoDox botnet represents more than a typical malware evolution; it illustrates a profound shift in cybercriminal strategy. Traditionally, botnets targeted singular device types with specific vulnerabilities, but RondoDox’s “exploit shotgun” approach marks a new, more ruthless era. By integrating loader-as-a-service capabilities with Mirai and Morte, attackers can rapidly expand their reach, infecting a heterogeneous mix of devices that range from consumer-grade routers to enterprise servers. This diversification complicates threat detection and remediation because traditional security monitoring often focuses on specific device classes, leaving gaps that attackers can exploit.

Furthermore, the inclusion of vulnerabilities without CVE identifiers is particularly alarming. It indicates attackers are actively seeking out and weaponizing obscure or undocumented flaws—an area where most organizations have limited defensive strategies. This behavior underscores the growing sophistication of cybercriminal ecosystems and the importance of proactive vulnerability management.

The AISURU botnet example demonstrates how the RondoDox model feeds into broader global threats. With 300,000 compromised IoT devices acting as attack nodes, these botnets can generate enormous DDoS traffic, severely disrupting critical services and potentially influencing national cybersecurity landscapes. This raises concerns about the readiness of infrastructure, especially in regions relying heavily on IoT and SOHO network devices, where default credentials and unpatched software are commonplace.

Additionally, the global RDP attack campaigns reported by GreyNoise emphasize that botnet strategies are not confined to IoT. Attackers are targeting enterprise-grade services, revealing that even sophisticated IT systems remain vulnerable to well-coordinated attacks. The use of centralized control and fingerprinting in these operations also points to the likelihood of organized, professional criminal groups driving these campaigns rather than opportunistic hackers.

Organizations must respond by adopting multi-layered security frameworks, including continuous vulnerability assessments, network segmentation, and real-time monitoring. Leveraging AI-based threat detection can help identify abnormal traffic patterns indicative of botnet activity. Moreover, companies should prioritize patch management and consider endpoint hardening for IoT devices, which often remain the weakest link in global cybersecurity infrastructure.

RondoDox and similar campaigns also underline the importance of international collaboration in cybersecurity. As attacks originate from a diverse set of countries, unilateral defense strategies are insufficient. Coordinated intelligence sharing, cross-border law enforcement cooperation, and standardized security practices for IoT manufacturers are critical to mitigating these evolving threats.

In summary, RondoDox is not just a botnet; it’s a blueprint for the next generation of automated cyberattacks, demonstrating how digital ecosystems can be weaponized at unprecedented scale. Its expansion signifies the urgent need for organizations and governments to rethink conventional cybersecurity paradigms and implement proactive defenses that address the full spectrum of modern network vulnerabilities.

Fact Checker Results:

✅ RondoDox exploits over 50 vulnerabilities across more than 30 vendors.

✅ AISURU botnet controls approximately 300,000 compromised hosts globally.

❌ The majority of RDP attack traffic originates from centralized botnet control, not random independent sources.

Prediction:

RondoDox and its associated campaigns will likely continue to evolve, leveraging increasingly sophisticated loaders and multi-vector exploits. 🌐 Expect a surge in IoT-focused DDoS attacks over the next 12–18 months, with potential geopolitical implications as critical infrastructure becomes a target. ⚠️ Enterprises ignoring patch management and device security may face escalating disruptions and financial losses.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.stackexchange.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon