ThreatCluster

RondoDox v2 Botnet Expands Exploits by 650%, Targets Enterprise Systems

First seen 4 Nov 2025, 11:10 UTC Reddit 83% similarity 38

Article Content

Browse articles
ThreatCluster

RondoDox v2, an evolved IoT botnet, has shown a 650% increase in exploit vectors, now encompassing over 75 CVEs. The botnet has transitioned from targeting consumer devices like DVRs and routers to enterprise systems, utilizing new command and control infrastructure on compromised residential IPs. It supports 16 architecture variants and employs XOR obfuscation for its operations.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story