INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

RondoDox Botnet Exploits Critical HPE OneView Bug

| 2026-01-16 13:00 HIGH HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
A large-scale exploitation campaign of the critical HPE OneView bug, CVE-2025-37164, has been observed globally since January 7, with tens of thousands of automated attack attempts recorded. The attacks are attributed to the RondoDox botnet and have targeted government organizations, financial services, industrial manufacturers, and other sectors in countries including the United States, Australia, France, Germany, and Austria. Check Point telemetry shows that between 05:45 and 09:20 UTC on January 7 alone, over 40,000 attack attempts were made, with most of the activity coming from a single Dutch IP address known to be associated with threat actors. The attacks are believed to have been automated in nature, using an "exploit-shotgun" approach to build sprawling botnet networks for DDoS and other malicious activities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-37164, CVE-2025-55182 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Pre-compromise (ATT&CK mitigation for Botnet): This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-37164CVE-2025-37164 CVE-2025-55182CVE-2025-55182
Target & Sectors
DACH DACH BENELUX BENELUX FIVE_EYES FIVE_EYES governmentgovernment
Incident Timeline
‎2026/01/16
Threat actors using the RondoDox botnet have conducted large-scale, automated attacks exploiting a critical HPE OneView bug.
infrastructure Linux
Tactical Metrics
Metrics
infrastructure
​Linux
Affected Product
Intelligence Sources
The Register - Cybercrime 2026-01-16
Infosecurity-Magazine 2026-01-16