RondoDox Unveiled: Breaking Down a New Botnet Threat
A new botnet called RondoDox has been discovered, exploiting two high-risk vulnerabilities: CVE-2024-3721 and CVE-2024-12856. It targets Linux-based systems on various architectures, including ARM and MIPS. RondoDox uses sophisticated evasion techniques, such as XOR-encoded configuration data, custom libraries, and traffic mimicry to avoid detection. The malware implements multiple persistence methods, terminates specific processes, and renames system executables to disrupt critical functions. It can launch DDoS attacks using HTTP, UDP, and TCP protocols while disguising traffic as popular games and platforms. The botnet's C2 server has been identified, and it poses a significant threat due to its advanced capabilities and ongoing development.
Pulse ID: 6877cefe5b0c5cbde2f82d94
Pulse Link: https://otx.alienvault.com/pulse/6877cefe5b0c5cbde2f82d94
Pulse Author: AlienVault
Created: 2025-07-16 16:10:38
Be advised, this data is unverified and should be considered preliminary. Always do further verification.