BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

RondoDox Botnet Exploits 50+ Flaws in 30+ Vendors

RondoDox Botnet Expands to Over 50 Vulnerabilities, Employs Loader-as-a-Service Model, While AISURU and Coordinated RDP Attacks Threaten U.S. IoT and Remote Access Security

  • RondoDox botnet campaigns have expanded to target over 50 vulnerabilities across 30+ vendors.
  • Trend Micro detected a RondoDox attack on June 15, 2025, exploiting a TP-Link router vulnerability.
  • RondoDox now uses a loader-as-a-service model, co-delivering Mirai and Morte Malware payloads.
  • Another major DDoS botnet, AISURU, controls around 300,000 compromised IoT devices mostly in the U.S.
  • GreyNoise identified a coordinated botnet attack targeting U.S. Remote Desktop Protocol (RDP) services starting October 8, 2025.

Malware campaigns distributing the RondoDox botnet have broadened their reach, exploiting more than 50 security vulnerabilities across over 30 vendors as of mid-2025. A notable intrusion attempt occurred on June 15, 2025, targeting TP-Link Archer routers using the CVE-2023-1389 flaw.

- Advertisement -

Trend Micro described the campaign as using an “‘exploit shotgun’ approach,” attacking various internet-exposed devices such as routers, DVRs, NVRs, CCTV systems, and web servers. The RondoDox botnet combines its payload with Mirai and Morte malware under a loader-as-a-service infrastructure, increasing the threat’s detection difficulty.

Since its first documentation by Fortinet FortiGuard Labs in July 2025, RondoDox has targeted TBK DVRs and Four-Faith routers to build a botnet that launches distributed denial-of-service (DDoS) attacks using HTTP, UDP, and TCP protocols. Its current operations exploit 56 known vulnerabilities, including 18 without assigned CVE numbers, spanning vendors like D-Link, NETGEAR, Cisco, and Apache.

Recent findings by CloudSEK reveal that RondoDox’s loader-as-a-service botnet distributes malware through SOHO routers, IoT devices, and enterprise applications by exploiting weak credentials, unsanitized inputs, and outdated security flaws.

Meanwhile, the DDoS botnet AISURU reportedly controls approximately 300,000 compromised IoT devices, primarily within internet providers like AT&T, Comcast, and Verizon in the United States. Security journalist Brian Krebs noted AISURU as one of the largest botnets responsible for record-setting DDoS attacks. An operator linked to this botnet, known as Forky, is based in Sao Paulo, Brazil, and associated with a DDoS mitigation service called Botshield.

- Advertisement -

Additionally, GreyNoise identified a coordinated botnet attack wave targeting Remote Desktop Protocol (RDP) services in the United States. Beginning October 8, 2025, this operation involves over 100,000 unique IP addresses from more than 100 countries, with significant traffic from Brazil, Argentina, Iran, China, Mexico, Russia, South Africa, and Ecuador. The attackers use two main techniques: RD Web Access timing attacks and RDP web client login enumeration. GreyNoise noted that most IPs share similar TCP fingerprints, indicating centralized control.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin’s Bear-Market Low Could Be Higher: Research

New research from Galaxy Digital suggests Bitcoin's bear market bottom could be higher than...

Blockchain Boosts ESG Data Credibility via Tokenization

Blockchain technology offers a solution for building tamper-resistant, shared ESG records that multiple stakeholders...

Google Sues Chinese Hackers Over Gemini AI Phishing

Google has filed a lawsuit to dismantle a Chinese cybercrime network using its Gemini...

AI Agents Fall Short: GPT-5, Gemini Vulnerable to Hacks

AI agents built with models like GPT-5 and Gemini remain highly vulnerable to prompt...

Warren: 11M Years To Earn Musk Wealth After IPO

Senator Elizabeth Warren proposed a wealth tax after Elon Musk became the world's first...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Key TakeawaysA Deep Dive into the Top Bitcoin Casinos of 2025Bitcoin Casino Comparison Table1. Stake.com: Best for Variety & Integrated Sports Betting2. BC.Game: Best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading