Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Tracking RondoDox: Malware Exploiting Many IoT Vulnerabilities

released on 2025-11-26 @ 09:54:19 AM
A new threat actor is distributing the RondoDox malware, a variant of Mirai, targeting IoT devices. The actor uses residential IP addresses for distribution and employs over a dozen exploits to target various IoT vulnerabilities. The malware's first stage is a shell script that attempts to disable security measures, remove competing malware, and download architecture-specific second-stage binaries. The campaign has been active since July 2025, with consistent use of a handful of distribution points. The actor targets home routers and other IoT devices using multiple CVEs and generic command injection attempts.