2026年1月13日に RondoDox について報告しましたが 1、実質的に暗号通貨 Monero のマイニングに特化していたため、当時は DDoS 機能については触れませんでした。他の IoT マルウェア同様に本体には DDoS 機能が実装されていますが、マイニングツールをダウンロードして起動した後は、DDoS 攻撃はほとんど観測されず、C2との接続を維持するために keepalive コマンドを定期的に繰り返すだけでした。しかし、5月になり、NICT サイバー脅威分析室は、RondoDox が DDoS 攻撃を開始したことを確認しました。2025年7月の大規模なエクスプロイトから約10ヶ月も経っていました。
[Read More]RondoDox to begin DDoS attacks
On January 13 2026, we have only reported that the RondoDox is mining Monero 1 though it has the ability of DDoS attack like the other IoT botnets. The reason we didn’t report about the DDoS attack functionality was that the malware itself was only keeping a connection with the command and control (C2) server by repeating keepalive commands except a few DDoS attack trials while the downloaded mining tool was running separately for a long time. About 10 months after the massive exploitation in July 2025, NICT Cyber Threat analysis Office has identidied that the RondoDox C2 began to send the DDoS attack commands in May 2026.
[Read More]暗号通貨のマイニングをするRondoDox
2025年第3四半期にNICTERで観測されたRondoDoxの最新の動向を報告します。
マルウェアの更新
RondoDoxのC2通信仕様では、C2サーバから送ったシェルコマンドをマルウェアに実行させることが可能で、このコマンドによりマルウェアの更新が行われます。
[Read More]