Find notable cyber news and cases, enriched with sources, timelines, and signals.

RondoDox botnet shotgun exploit activity across network devices

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The RondoDox botnet is escalating a “shotgun” exploit operation against routers, DVRs, NVRs, CCTV systems, web servers, and other network gear, raising the risk of mass compromise. It now targets 56 vulnerabilities across more than 30 vendors, including CVE-2023-1389, CVE-2024-3721, and CVE-2024-12856. Compromised devices are being used for cryptocurrency mining, DDoS attacks, and enterprise network intrusion, while payloads are being co-packaged with Mirai/Morte to improve evasion.

Related Happenings

NCSC-UK joint advisory on covert botnets and proxy networks

Public Sector Action
H score66 First: 23.04.2026 15:28 Last: 23.04.2026 15:28 Sources 1

About this happening: NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide maliciou...

China-nexus hijacked-device proxy network campaign

Campaign
H score43 First: 23.04.2026 15:28 Last: 23.04.2026 15:28 Sources 1

About this happening: NCSC-UK and international partners warned on 2026-04-23 that China-nexus hackers are using large-scale proxy networks built from hijacked consumer devices, including *...

Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign

Campaign
H score38 First: 22.04.2026 23:04 Last: 22.04.2026 23:04 Sources 1

About this happening: The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...

D-Link DIR-823X command-injection RCE (CVE-2025-29635)

Vulnerability
H score40 First: 22.04.2026 23:04 Last: 22.04.2026 23:04 Sources 1

About this happening: CVE-2025-29635 is now being actively exploited on D-Link DIR-823X routers, turning a command-injection flaw into remote command execution and botnet enrollment...

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Timeline

  1. 10.10.2025 15:06 2 articles · 9mo ago

    RondoDox botnet shotgun exploit activity across network devices

    Initial Disclosure

    RondoDox first appeared in mid-2025 as a botnet exploiting CVE-2023-1389 on TP-Link Archer AX21 routers. It then moved to additional router and DVR flaws before broadening into a much wider device set.

    Show sources