RondoDox edge and web exploitation
Case score 60
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 60
- Main story score
- 56
- Related evidence lift
- +4 / 20
- Contributing updates
- 2
- Context updates
- 0
- Campaign Anchors the RondoDox operation and its exploit-shotgun, loader-as-a-service behavior. main
- Exploitation Wave Adds earlier edge-device exploitation and the CVE-2023-1389 router abuse that broadens the campaign. contributes
- Malware Activity Adds later Next.js malware deployment, React2Shell exploitation, and payload staging details. contributes
Overview
Latest development Open development history RondoDox begins deploying botnet clients against Next.js servers Three days after scanning begins, RondoDox starts deploying botnet clients against vulnerable Next.js servers and stages payloads including a coinminer (/nuts/poop), a botnet loader and health checker (/nuts/bolts), and a Mirai variant (/nuts/x86).
-
RondoDox React2Shell activity and exposure totals are summarized
RondoDox activity against React2Shell-exposed Next.js servers includes over 40 exploit attempts within six days in December, hourly IoT exploitation waves targeting Linksys and Wavlink routers, and loader behavior that removes competing botnet malware, enforces persistence via /etc/crontab, and kills non-whitelisted processes every 45 seconds; more than 94,000 internet-exposed assets were vulnerable to React2Shell as of December 30.
-
RondoDox exploits CVE-2023-1389 on TP-Link Archer routers
Trend Micro detected a RondoDox intrusion attempt on June 15, 2025, when attackers exploited CVE-2023-1389 against TP-Link Archer routers. The flaw had already been under repeated active exploitation after its late-2022 disclosure.
-
RondoDox expands into multivector loader-as-a-service operations
Trend Micro described RondoDox as using an exploit shotgun strategy to target more than 50 vulnerabilities across over 30 vendors and a broad set of internet-exposed infrastructure, including routers, digital video recorders, network video recorders, CCTV systems, web servers, and other network devices. The campaign also broadened distribution through a loader-as-a-service infrastructure that co-packages RondoDox with Mirai/Morte payloads, increasing detection and remediation urgency.
-
RondoDox edge-device exploitation wave
In **May**, RondoDox began with exploitation of **one critical** and **one high-severity n-day** vulnerability in popular **DVRs** and **routers**. At that stage, the activity was narrower but already pointed at hard-to-patch edge devices.