Skip to content
ThreatCluster

RondoDox v2 Botnet Expands Exploits by 650%, Targets Enterprise Systems

First seen 4 Nov 2025, 11:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

RondoDox v2, an evolved IoT botnet, has shown a 650% increase in exploit vectors, now encompassing over 75 CVEs. The botnet has transitioned from targeting consumer devices like DVRs and routers to enterprise systems, utilizing new command and control infrastructure on compromised residential IPs. It supports 16 architecture variants and employs XOR obfuscation for its operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 199d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track RondoDox and AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed