CondiBot Malware and Monaco Miner Broaden Attacks On Network Hardware

The enterprise attack surface has fundamentally shifted, with financially motivated attackers now systematically exploiting network infrastructure alongside nation-state groups.

Recent findings reveal two new malware variants, CondiBot and Monaco, that aggressively target network hardware for DDoS attacks and crypto-mining.

This trend aligns with ongoing industry concerns regarding the rapid evolution of malware distribution and APT hacking tactics.

These campaigns demonstrate that network hardware exploitation is no longer exclusive to advanced persistent threats but is now actively leveraged by a wider variety of cybercriminals.

Emerging Threats: CondiBot and Monaco Miner

On March 6, 2026, researchers captured samples of two distinct malware families targeting network infrastructure, regardless of the vendor.

Consistent with previous technical security reporting, the details of these threats emphasize the critical need for enhanced device-level visibility.

The first variant, CondiBot, is an evolution of the Mirai-derived Condi DDoS botnet. Written in C, this multi-architecture binary is designed to compromise Linux devices and convert them into remote-controlled nodes for large-scale network attacks.

Mechanism of Attack (Source: eclypsium)
Mechanism of Attack (Source: eclypsium)

Unlike previous versions, this new strain uses a robust delivery mechanism that cycles through multiple transfer capabilities, such as GET and CURL, to ensure a successful payload drop.

Once executed, it disables system reboots, establishes persistence, and actively hunts down and kills competing botnets, such as the newly added “/bin/sora”.

Key technical details of the CondiBot variant include:

  • Target Architecture: Operates across ARM, MIPS, and x86 variants.
  • C2 Infrastructure: Connects to IP 65.222.202.53 over port 80.
  • Unique Identifiers: Contains the internal string “QTXBOT”, which was previously unknown to major threat intelligence platforms.
  • Attack Capabilities: Registers 32 distinct attack handlers for various network flooding techniques.
Mechanism of Attack (Source: eclypsium)
Mechanism of Attack (Source: eclypsium)

The second threat, dubbed “Monaco”, is an active cryptojacking operation written in Go 1.24.0.

This malware scans the internet for exposed SSH servers, routers, and IoT devices and attempts to brute-force access using hardcoded credentials such as “root” and “admin”.

Upon successful compromise, Monaco deploys Monero cryptocurrency miners to generate revenue using compromised devices as free computing power.

The Strategic Shift To Network Devices

The rise of CondiBot and Monaco aligns with a broader escalation in attacks against network technology. The 2025 Verizon Data Breach Investigation Report highlighted an 8x increase in exploitation of vulnerabilities in network devices.

Furthermore, Google Threat Intelligence reported that nearly a quarter of all zero-day vulnerabilities exploited in 2025 specifically targeted network and security appliances.

SpecificationCondiBot Variant (DDoS Botnet)“Monaco” Variant (SSH Scanner & Crypto Miner)
Malware FamilyMirai derivative (DDoS executor)Cryptominer
Filenameexecutorexecutor
Language/CompilerC (statically linked, stripped)Go 1.24.0 (built 2025-02-11)
File TypeELF 64-bit x86_64, statically linked, strippedELF 64-bit LSB executable, x86-64, statically linked

As threat actors continue to weaponize network infrastructure, eclypsium organizations must look beyond traditional endpoint security.

Addressing these blind spots requires specialized detection capabilities that monitor firmware and anomalous behavior in network edge equipment.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories