This dangerous new botnet is shooting off attacks across the world faster than can be tracked – here’s what we know about RondoDox

  • RondoDox botnet exploits 56 vulnerabilities across 30+ internet-connected device types
  • Its “exploit shotgun” approach is noisy, attracting defenders but compromising diverse hardware
  • Patching devices, updating firmware, and isolating networks help prevent botnet infiltration

Security researchers are warning about RondoDox, a noisy new botnet targeting dozens of vulnerabilities in more than 30 devices.

Usually, cybercriminals would focus on one vulnerability in a specific endpoint – either a zero-day flaw, or an old, unpatched vulnerability, and try to build their botnet around that. RondoDox, however, is completely different. It currently targets 56 vulnerabilities in all sorts of hardware, with new targets being constantly added.

Security researchers from Trend Micro call this strategy “exploit shotgun”. It works well, but it’s also loud and noisy and draws the attention of defenders rather quickly.

Other services intact

A botnet is a network of bots – compromised endpoints such as routers, DVRs, CCTV systems and web cameras, smart home devices, and other internet-connected hardware.

They are used for all sorts of criminal activity, from launching Distributed Denial of Service (DDoS) attacks, to renting residential proxy services to other hackers.

RondoDox is a herald of things to come, CyberInsider argues. Cybercriminals are moving into “automated, modular exploitation of aging infrastructure at scale,” the publication claims.

The list of vulnerable devices is quite extensive, and includes heavy-hitters such as QNAP, D-Link, Netgear, TP-Link, and Linksys.

The vulnerability list includes all sorts of flaws, from those found during Pwn2Own competitions, to some that are years old and found in devices that are past their end-of-life (EoL) status.

Luckily, defending against these flaws is easy, since most of them have a patch already available. Therefore, installing the patch is the way to go. Also, keeping the firmware updated at all times, and making sure no unsupported devices are running, is a good rule of thumb not to get assimilated into a malicious botnet.

Since some of the flaws don’t have an assigned CVE and could be a zero-day, there are other measures companies should take. That includes segmenting the network, isolating critical data from internet-facing hardware and guest connections, and making sure the passwords and other login credentials are unique, strong, and frequently updated.

At press time, the campaign is still active.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

Build a cheap starter home theater: the best TV, soundbar, and streamer combos

The nights are drawing in, the days are getting colder, and – whisper it – the holidays are growing nearer, all of which makes...

The Lavazza Assoluta adjusts its own brew settings to suit your beans, but does it make a good espresso?

Last month, Italian coffee company Lavazza revealed its latest espresso machine, the Lavazza Assoluta. It's a good-looking bean-to-cup machine with an interesting selling point:...

“We turn microns into milliseconds” – How Hexagon hopes to be Oracle Red Bull Racing’s extra boost in winning Formula 1 success

We’ve all heard it a hundred times; Formula 1 is about speed. But, as the cars get bigger and faster, and track limits get...

Apple’s rumored iPhone 18 upgrade will put the same amount of RAM in all four models

The iPhone 18 could be in line for a RAM upgradeIt might get 12GB of RAM to match the other iPhonesMore RAM means better...

Have your say: are iPhones overrated?

As a technology journalist of more than a decade, I've seen iPhone-centric Apple events come and go. Yet for TechRadar, the usual September Apple...

The OM System OM-5 II just took top spot in our travel camera guide – here are 5 reasons why it’s so good for...

The OM System OM-5 II doesn’t have a big full-frame sensor, AI autofocus, 8K video or any of the other headline-grabbing features of the...

How to watch Real Madrid vs Barcelona: live streams, channels, previews and team news for the first El Clasico of 2025/26

Real Madrid vs Barcelona Kick off: 3.15 pm BST/ 10.15 am ET, Sunday, October 26Stream on ESPN via Sling (US) and Premier Sports (UK)Access...

How to watch Aston Villa vs Man City: live stream Premier League 2025/26 game, TV channels, preview

Aston Villa vs Man City: Oct. 26, 2025Time: 9am ET / 6am PT / 2pm BST / 11pm AESTBest Stream: USA Network via YouTube...

How to watch Arsenal vs Crystal Palace: live stream Premier League 2025/26 game, TV channels, preview

Arsenal vs Crystal Palace: Oct. 26, 2025Time: 9am ET / 6am PT / 2pm BST / 11pm AESTBest Streams: Peacock (US) / Sky Sports...

This air fryer crispy sesame chicken is the closest I’ve come to replicating my favorite takeout

If I see the words 'sticky sauce' on any menu, chances are I’m ordering whatever food it comes with. Even more so when I’m...