The RondoDox botnet is being distributed by malware attacks that have broadened their scope to target and exploit over 30 manufacturers and more than 50 vulnerabilities.
According to Trend Micro, the activity, which is similar to a “exploit shotgun” strategy, has targeted a variety of internet-exposed infrastructure, such as routers, CCTV systems, digital video recorders (DVRs), network video recorders (NVRs), web servers, and other network devices.
According to the cybersecurity firm, on June 15, 2025, it discovered a RondoDox intrusion attempt in which the attackers took advantage of CVE-2023-1389, a TP-Link Archer router security hole that has been actively exploited numerous times since it was initially made public in late 2022.
In July 2025, Fortinet FortiGuard Labs published the first documentation of RondoDox, which described attacks against TBK DVRs and Four-Faith routers that used the HTTP, UDP, and TCP protocols to recruit them into a botnet for launching distributed denial-of-service (DDoS) attacks read more about Researchers Warn RondoDox Botnet is Weaponizing Over 50 Flaws Across 30+ Vendors.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
