Cybersecuritynews RondoDox Botnet Grows, Exploiting 174 Vulnerabilities via Residential IPs
Article Content
- •RondoDox botnet exploits 174 vulnerabilities using residential IP infrastructure.
- •First detected in May 2025, it has shown significant growth and activity.
- •Weak security controls in consumer devices contribute to the botnet's expansion.
The RondoDox botnet has rapidly expanded, now exploiting 174 vulnerabilities using compromised residential IP addresses. First detected in May 2025, it has generated significant traffic in security honeypots, indicating its active presence. The botnet operates similarly to Mirai, leveraging weak security controls in consumer devices, which are often shipped without adequate patches. This widespread exploitation increases the global attack surface, affecting numerous devices and networks. The botnet's automated capabilities allow it to chain vulnerabilities effectively, raising concerns among security professionals. Vendors are urged to improve security practices to mitigate risks associated with such automated threats. Current status indicates ongoing activity and potential for further growth as new vulnerabilities are discovered.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Mirai in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
KATARU IoT Malware Exploits Linux Vulnerabilities for DDoS Attacks The KATARU malware targets internet-exposed IoT devices using Telnet credential brute-forcing. Once access is gained, it attempts to escalate privileges using public Linux exploits, including CVE-2026-46300, CVE-2026-43284, and CVE-2026-31431. The malware combines Mirai-style DDoS capabilities with encrypted…