HomeSecurityRondoDox botnet: Targets dozens of devices via 56 n-day vulnerabilities

RondoDox botnet: Targets dozens of devices via 56 n-day vulnerabilities

A new, highly aggressive botnet dubbed RondoDox has begun to spread rapidly, targeting dozens of types of connected devices such as DVRs, NVRs, CCTV cameras, and Wi-Fi routers. Cybersecurity researchers from Trend Micro and FortiGuard Labs have detected its activity since June, and initial findings indicate that this is one of the most extensive and multi-faceted IoT exploitation campaigns in recent years.

RondoDox botnet n-day

The “exploit shotgun” tactic: Attacks on anything that moves

RondoDox does not rely on a single vulnerability; instead, it employs what is known as an “exploit shotgun” strategy. In this method, the botnet uses dozens of exploits simultaneously in order to increase the chances of infecting as many devices as possible. Although the activity is “noisy” and easily detected, the volume of attacks outweighs the noise, allowing the botnet to quickly establish itself in home and corporate networks.

See also: Vulnerabilities in 7-Zip allow RCE attacks

Researchers estimate that RondoDox exploits 56 vulnerabilities in over 30 devices, some of which were first revealed at the hacking competition Pwn2Own. This source of information appears to be a treasure trove for botnet creators, who are rushing to weaponize the latest revelations before manufacturers can release security patches.

From Pwn2Own to the battlefield

Pwn2Own is one of the most well-known cybersecurity competitions, organized twice a year by Zero Day Initiative (ZDI) . During the events, white-hat researchers present zero-day exploits for common products such as routers, NAS, and cameras. However, cybercriminals seem to be following these presentations closely, turning the findings into weapons.

RondoDox botnet: Targets dozens of devices via 56 n-day vulnerabilities

A typical example is the exploitation of CVE-2023-1389, a flaw in the TP-Link Archer AX21 router, which was disclosed at Pwn2Own Toronto 2022. RondoDox not only incorporated this vulnerability, but also many others, affecting manufacturers such as QNAP, D-Link, Netgear, TRENDnet, TOTOLINK and Tenda. The list is constantly growing, showing that the botnet is evolving rapidly.

See also: PoC Exploit for Code Execution Vulnerability in Nothing Phone

Here is a list of n-day vulnerabilities (post-2023) that RondoDox has used in its arsenal:

  • Digiever – CVE-2023-52163
  • QNAP – CVE-2023-47565
  • LB-LINK – CVE-2023-26801
  • TRENDnet – CVE-2023-51833
  • D-Link – CVE-2024-10914
  • TBK – CVE-2024-3721
  • Four-Faith – CVE-2024-12856
  • Netgear – CVE-2024-12847
  • AVTECH – CVE-2024-7029
  • TOTOLINK – CVE-2024-1781
  • Tenda – CVE-2025-7414
  • TOTOLINK – CVE-2025-1829
  • Meteobridge – CVE-2025-4008
  • Edimax – CVE-2025-22905
  • Linksys – CVE-2025-34037
  • TOTOLINK – CVE-2025-5504
  • TP-Link – CVE-2023-1389

Old devices, new threats

One of the most worrying aspects of the case is that a large portion of the targeted devices have reached their end of life (EoL). This means that their manufacturers are no longer issuing updates, leaving them vulnerable to attacks. However, even newer models remain unprotected, as many users neglect to install firmware updates.

Trend Micro also identified 18 additional exploits for flaws without a CVE identifier, targeting products such as D-Link NAS, TVT and LILIN DVRs, Fiberhome, ASMAX and Linksys routers , and Brickcom cameras. This is a broad range of devices, many of which are used in home environments or small businesses without specialized security support.

See also: PoC Exploit for Code Execution Vulnerability in Nothing Phone

RondoDox botnet: Targets dozens of devices via 56 n-day vulnerabilities

How to protect yourself from RondoDox

Tackling a botnet of this size requires a combination of technical and organizational measures. Experts recommend:

  • Instant installation of the latest firmware updates on all connected devices.
  • Replacing old or unsupported models (EoL) with more modern and secure ones.
  • Change default passwords and use strong, unique combinations.
  • Network segmentation: separate IoT devices from critical data or corporate endpoints.
  • Regularly check logs and unusual activity, especially for unknown outbound traffic connections.

The message behind RondoDox

RondoDox is further proof that IoT device security remains the weakest link in the digital chain . Cybercriminals are exploiting the vast number of unprotected devices that connect to the internet every day, turning them into weapons for DDoS attacks, data mining or surveillance.

See also: GitLab Security Update – Fixing Multiple Vulnerabilities

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The challenge is now not only technical, but also cultural: a change in mindset is required from users, businesses and manufacturers so that security is no longer considered a secondary priority. RondoDox is just the latest reminder that in the world of cyber, the “if” a device will be attacked has been replaced by “when.”

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS