Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructureembedded-device-vulnerabilityrapid-weaponizationgovernment-vulnerability-catalog

RondoDox Botnet Campaign Exploiting Dozens of N-Day Vulnerabilities in Internet-Exposed Devices

Updated 3mo agoFirst seen Oct 9, 20256 sources

The RondoDox botnet has emerged as a significant threat, actively targeting a wide array of internet-exposed infrastructure by exploiting over 50 known vulnerabilities, many of which were first disclosed during Pwn2Own hacking competitions. Security researchers from Trend Micro and FortiGuard Labs have observed the botnet leveraging an 'exploit shotgun' approach, simultaneously deploying numerous exploits to maximize infection rates across diverse device types. The campaign has been active globally since at least June 2025, with attacks focusing on routers, digital video recorders (DVRs), network video recorders (NVRs), CCTV systems, web servers, and other network devices from more than 30 vendors. Notably, the botnet exploits both recent and older vulnerabilities, including CVE-2023-1389 in the TP-Link Archer AX21 Wi-Fi router, which was originally demonstrated at Pwn2Own Toronto 2022 and previously targeted by Mirai. The list of exploited vulnerabilities includes CVE-2024-3721, CVE-2024-12856, and many others affecting brands such as Digiever, QNAP, LB-LINK, TRENDnet, D-Link, TBK, Four-Faith, Netgear, AVTECH, TOTOLINK, Tenda, Meteobridge, Edimax, and Linksys. Many of these vulnerabilities are now included in CISA’s Known Exploited Vulnerabilities (KEV) catalog, underscoring the urgency for organizations to patch affected systems. Devices that have reached end-of-life are particularly at risk, as they are less likely to receive security updates, making them attractive targets for the botnet operators. The campaign exposes organizations to risks including data exfiltration, persistent network compromise, and operational disruption, especially for those with internet-facing infrastructure. Security experts recommend prioritizing the patching of all listed vulnerabilities, conducting regular vulnerability assessments, segmenting networks to limit lateral movement, and continuously monitoring for anomalous device activity. Trend Micro has indicated that its solutions provide protection against the vulnerabilities exploited by RondoDox, offering mitigation while patching is underway. The rapid weaponization of vulnerabilities demonstrated at Pwn2Own highlights the need for organizations to monitor disclosures from such competitions and act swiftly to secure their environments. The RondoDox botnet’s ability to quickly expand its arsenal of exploits demonstrates a high level of adaptability and threat actor sophistication. The campaign’s global reach and the diversity of targeted devices suggest that organizations across multiple sectors are at risk. The use of mass n-day exploitation, rather than relying solely on zero-day vulnerabilities, allows the botnet to compromise a large number of devices that may not be promptly patched. Security researchers emphasize the importance of defense-in-depth strategies to mitigate the impact of such widespread exploitation campaigns. The ongoing activity of RondoDox serves as a stark reminder of the persistent threat posed by botnets leveraging known vulnerabilities in widely deployed network devices.

Share:
RondoDox Botnet Campaign Exploiting Dozens of N-Day Vulnerabilities in Internet-Exposed Devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 9, 20259mo ago

Researchers disclose RondoDox targeting 56 flaws across 30+ device types

Trend Micro and other outlets reported that RondoDox was actively exploiting 56 vulnerabilities, including 38 CVEs and 18 unassigned command-injection flaws, across more than 30 vendors and device types worldwide. The disclosure emphasized the botnet's rapid weaponization of n-day and Pwn2Own-related vulnerabilities and prompted calls for urgent patching and exposure reduction.

Aug 1, 202511mo ago

RondoDox expands into a loader-as-a-service operation

Trend Micro reported that RondoDox later evolved beyond initial exploitation into a loader-as-a-service model. This expansion allowed payloads such as RondoDox and Mirai/Morte to be co-packaged, broadening the campaign's reach and impact.

Jul 1, 20251y ago

RondoDox is first publicly described targeting TBK and Four-Faith devices

In mid-2025, RondoDox was first publicly described as exploiting TBK DVRs and Four-Faith routers via CVE-2024-3721 and CVE-2024-12856. The attacks were used to gain shell access and deploy multi-architecture payloads.

Jun 1, 20251y ago

RondoDox campaign becomes active globally

Researchers reported that the RondoDox botnet has been active globally since June, targeting internet-exposed infrastructure. The campaign used an 'exploit shotgun' method to try many exploits across routers, DVRs, NVRs, CCTV systems, web servers, and other devices.

Mar 1, 20233y ago

RondoDox begins exploiting CVE-2023-1389 in early activity

Trend Micro said early RondoDox activity was tied to exploitation of CVE-2023-1389 in TP-Link Archer AX21 routers. This showed the botnet rapidly weaponizing a vulnerability first disclosed through Pwn2Own.

Dec 1, 20224y ago

Pwn2Own Toronto 2022 flaw later tied to RondoDox is disclosed

A vulnerability in the TP-Link Archer AX21 router, later tracked as CVE-2023-1389, was publicly demonstrated at Pwn2Own Toronto 2022. Trend Micro later linked early RondoDox activity to weaponization of this bug, highlighting the botnet's use of competition-disclosed flaws.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

70 LINKEDOpen in app
Vulnerabilities
37 linked
OS Command Injection in TOTOLINK X18 setMtknatCfgOS Command Injection in Tenda O3V2 /goform/setPingInfoUnauthenticated OS Command Injection in D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgiOS Command Injection in QNAP VioStor NVR QVR Firmware 4.xUnauthenticated Command Injection in TP-Link Archer AX21 /locale EndpointUnauthenticated OS Command Injection in Linksys E-Series RoutersOS Command Injection in TBK DVR-4104 and DVR-4216Authentication Bypass and Root Command Execution in NETGEAR DGN1000 setup.cgiOS command injection in Digiever DS-2105 Pro time_tzsetup.cgi (ntp parameter)Command Injection in TOTOLINK X6000R AX3000 setWizardCfgCommand Injection in TOTOLINK X2000R /boafrm/formWscCommand Injection in Smartbedded Meteobridge /public/template.cgiUnauthenticated OS command injection in AVTECH IP camera brightness function (CVE-2024-7029)Command Injection in LB-LINK Multiple Routers /goform/set_LimitClient_cfgCommand Injection in RE11S v1.11 /goform/mpOS Command Injection in Four-Faith F3x24/F3x36 apply.cgiCommand Injection in TRENDnet TEW-411BRPplus debug.cgiUnauthenticated Command Injection in Billion 5200W-T Remote System LogShellshockUnauthenticated Command Injection in ZyXEL P660HN-T1A ViewLog.asp Remote System LogRCE in Cisco RV110W/RV130W/RV215W Web Management InterfaceCommand Injection in Hytec Inter HWL-2511-SS popen.cgiAuthenticated command injection in NETGEAR mini_httpd funjsq_access_tokenBuffer Overflow in Belkin N750 Router MiniHttpd login.cgi jump ParameterCommand injection in D-Link DNS-320 system_mgr.cgi leading to RCEUnauthenticated command injection RCE in multiple D-Link routers via PingTest/apply_sec.cgiCommand Injection in D-Link DIR-816 /goform/SystemCommandCommand Injection in NETGEAR R-Series and D-Series Routers cgi-bin HandlerD-Link DIR-645 HNAP SOAPAction Command InjectionDasan GPON Router Authentication Bypass via ?images ParameterApache HTTP Server path traversal and possible RCE in 2.4.49/2.4.50Command Injection in Tenda AC15 AC1900 goform/setUsbUnloadPath Traversal in XiaoBingBy TeaCMS 2.0 /admin/uploadAuthentication Bypass in TP-Link TL-WR840N/TL-WR841N CGI InterfaceAuthenticated OS Command Injection in Nexxt Amp300 goform/sysTools ping featureApache HTTP Server 2.4.49 Path Traversal and Possible RCEOS Command Injection in D-Link DIR820LA1_FW105B03 (ping_addr parameter)
Malware
1 linked
Organizations
32 linked
Trend MicroTendaTP-LinkTotolinkQNAP SystemsLinksysD-LinkFiberhomeNetgearBrickcomTvtAvtechPwn2OwnFour-FaithFortinetASMAXLilinLb-LinkEdimaxTrendnetBillionCisco SystemsRondoDoxDigieverBleepingComputerGNU ProjectTBKZyxel CommunicationsApache Software FoundationBelkinMeteobridgeDasan
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.