Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructureactively-exploited-vulnerabilityembedded-device-vulnerabilityend-of-life-software

RondoDox Botnet Exploits Critical Asus Router RCE for Root Access

Updated 28d agoFirst seen May 23, 20265 sources

Researchers reported that the RondoDox botnet is actively exploiting CVE-2018-5999, a critical remote code execution flaw in Asus routers that lets unauthenticated attackers gain root access. VulnCheck said it observed in-the-wild exploitation beginning on May 17, marking the first known real-world abuse of the 2018 vulnerability even though public exploit code has been available for years. The flaw affects widely deployed consumer routers, with more than 1 million Asus devices believed to be exposed online.

RondoDox, a Linux-focused botnet first seen in mid-2025 and often described as a Mirai variant, uses multi-stage mass exploitation against end-of-life and IoT devices, frequently chaining older embedded-device CVEs before deploying malware and connecting to command-and-control infrastructure. Researchers said the botnet is primarily used for denial-of-service attacks and appears to rely on compromised residential IP addresses for hosting, suggesting its operators closely track vulnerability disclosures and rapidly weaponize older flaws in consumer networking gear.

Share:
RondoDox Botnet Exploits Critical Asus Router RCE for Root Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 22, 20261mo ago

Researchers publicly report RondoDox attacks on Asus routers

On May 22, 2026, reporting disclosed that RondoDox was exploiting CVE-2018-5999 in Asus routers at scale. The coverage also highlighted the botnet's use of older embedded-device CVEs, compromised residential IPs, and likely monitoring of vulnerability disclosures to weaponize flaws quickly.

May 17, 20261mo ago

VulnCheck observes RondoDox exploiting CVE-2018-5999

VulnCheck began observing in-the-wild exploitation of CVE-2018-5999 by the RondoDox botnet on May 17, 2026. Researchers said this was the first known active exploitation of the long-public Asus router vulnerability.

Jul 15, 202511mo ago

F5 Labs begins tracking RondoDox exploiting multiple IoT vulnerabilities

F5 Labs reported tracking the RondoDox threat actor since July 15, 2025 as it targeted IoT and other Linux-based devices using numerous command-injection and remote-code-execution exploits. The researchers documented its limited set of distribution IPs, rotating rondo.XXX.sh first-stage scripts, architecture-specific payloads, and indicators including the email address bang2012@tutanota.de.

Tracking RondoDox: Malware Exploiting Many IoT Vulnerabilities | F5 Labs
Jun 1, 20251y ago

RondoDox botnet first observed in the wild

Researchers first saw the Linux-focused RondoDox botnet in mid-2025. It was described as a Mirai variant that targets end-of-life and IoT devices using multi-stage exploitation.

Jan 1, 20188y ago

Public exploit code for CVE-2018-5999 becomes available

Exploit code for CVE-2018-5999, a critical remote code execution flaw in Asus routers allowing unauthenticated root access, was publicly available in 2018. Despite this, no real-world exploitation had been reported for years.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Affected products
1 linked
Asus Routers
Organizations
3 linked
ASUSVulnCheckBitsight
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

RondoDox Botnet Exploits Critical Asus Router RCE for Root Access | Mallory