INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
RondoDox Botnet Exploits Critical HPE OneView Bug
| 2026-01-16 13:00 HIGH HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
A large-scale exploitation campaign of the critical HPE OneView bug, CVE-2025-37164, has been observed globally since January 7, with tens of thousands of automated attack attempts recorded. The attacks are attributed to the RondoDox botnet and have targeted government organizations, financial services, industrial manufacturers, and other sectors in countries including the United States, Australia, France, Germany, and Austria. Check Point telemetry shows that between 05:45 and 09:20 UTC on January 7 alone, over 40,000 attack attempts were made, with most of the activity coming from a single Dutch IP address known to be associated with threat actors. The attacks are believed to have been automated in nature, using an "exploit-shotgun" approach to build sprawling botnet networks for DDoS and other malicious activities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-37164, CVE-2025-55182 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
• Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-37164CVE-2025-37164
CVE-2025-55182CVE-2025-55182
Target & Sectors
DACH
DACH
BENELUX
BENELUX
FIVE_EYES
FIVE_EYES
governmentgovernment
Incident Timeline
2026/01/16
Threat actors using the RondoDox botnet have conducted large-scale, automated attacks exploiting a critical HPE OneView bug.
Click on any entity below to view its context and source!
infrastructure
Linux
Check Point has tied the activity to RondoDox, a Linux-based botnet that weaponizes publicly known vulnerabilities across routers, DVRs, web servers, and other devices,
using an "exploit-shotgun" approach
to build sprawling botnet networks for DD…
The activity has been attributed to the Linux-based RondoDox
botnet
and Check Point warned the campaign represents a sharp escalation from early probing attempts to large-scale, automated attacks.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
Check Point has tied the activity to RondoDox, a Linux-based botnet that weaponizes publicly known vulnerabilities across routers, DVRs, web servers, and other devices,
using an "exploit-shotgun" approach
to build sprawling botnet networks for DD…
The activity has been attributed to the Linux-based RondoDox
botnet
and Check Point warned the campaign represents a sharp escalation from early probing attempts to large-scale, automated attacks.
Intelligence Sources
The Register - Cybercrime
2026-01-16
RondoDox botnet linked to large-scale exploit of critical HPE OneView bug
The Register - Cybercrime
Infosecurity-Magazine
2026-01-16
RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation Wave
Infosecurity-Magazine
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:25
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
The Register
's
entity
9x
timeline
Temporal Reference
January 7
date
5x
target region
Target Country
Australia
country
3x
tactic
Cyber Operation Type
Botnet
tactic
2x
vulnerability
Exploited CVE
CVE-2025-37164
cve
2x
tactic
MITRE ATT&CK Technique
T1584.005 - Botnet
technique
2x
attribution
Attributing Entity
KEV
authority
Contextual Telemetry
Context Block
7 METRICS
source region
Origin Country
United States
country
industry
Targeted Sector
Government
sector
infrastructure
Affected Product
Linux
software
general metric
Attack Attempts
40,000
attack attempts
general metric
Perfect Severity Score
10
perfect severity score
vulnerability
CVSS Score
3
score
general metric
Score
3
score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.