Skip to content
RondoDox Botnet Grows, Exploiting 174 Vulnerabilities via Residential IPs

RondoDox Botnet Grows, Exploiting 174 Vulnerabilities via Residential IPs

First seen 17 Mar 2026, 00:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 19, 2026 at 02:12 UTC
  • •RondoDox botnet exploits 174 vulnerabilities using residential IP infrastructure.
  • •First detected in May 2025, it has shown significant growth and activity.
  • •Weak security controls in consumer devices contribute to the botnet's expansion.

The RondoDox botnet has rapidly expanded, now exploiting 174 vulnerabilities using compromised residential IP addresses. First detected in May 2025, it has generated significant traffic in security honeypots, indicating its active presence. The botnet operates similarly to Mirai, leveraging weak security controls in consumer devices, which are often shipped without adequate patches. This widespread exploitation increases the global attack surface, affecting numerous devices and networks. The botnet's automated capabilities allow it to chain vulnerabilities effectively, raising concerns among security professionals. Vendors are urged to improve security practices to mitigate risks associated with such automated threats. Current status indicates ongoing activity and potential for further growth as new vulnerabilities are discovered.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 191d ago How this analysis works

Timeline

2025-05-01
RondoDox botnet first detected.
2026-03-16
Gbhackers article published detailing botnet's capabilities.
2026-03-17
Cybersecuritynews article published with updated threat information.

More articles in this cluster (4)

Following this threat?

Track Mirai in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed