The enterprise attack surface has fundamentally shifted, with financially motivated attackers now systematically exploiting network infrastructure alongside nation-state groups.
Recent findings reveal two new malware variants, CondiBot and Monaco, that aggressively target network hardware for DDoS attacks and crypto-mining.
This trend aligns with ongoing industry concerns regarding the rapid evolution of malware distribution and APT hacking tactics.
These campaigns demonstrate that network hardware exploitation is no longer exclusive to advanced persistent threats but is now actively leveraged by a wider variety of cybercriminals.
Emerging Threats: CondiBot and Monaco Miner
On March 6, 2026, researchers captured samples of two distinct malware families targeting network infrastructure, regardless of the vendor.
Consistent with previous technical security reporting, the details of these threats emphasize the critical need for enhanced device-level visibility.
The first variant, CondiBot, is an evolution of the Mirai-derived Condi DDoS botnet. Written in C, this multi-architecture binary is designed to compromise Linux devices and convert them into remote-controlled nodes for large-scale network attacks.

Unlike previous versions, this new strain uses a robust delivery mechanism that cycles through multiple transfer capabilities, such as GET and CURL, to ensure a successful payload drop.
Once executed, it disables system reboots, establishes persistence, and actively hunts down and kills competing botnets, such as the newly added “/bin/sora”.
Key technical details of the CondiBot variant include:
- Target Architecture: Operates across ARM, MIPS, and x86 variants.
- C2 Infrastructure: Connects to IP 65.222.202.53 over port 80.
- Unique Identifiers: Contains the internal string “QTXBOT”, which was previously unknown to major threat intelligence platforms.
- Attack Capabilities: Registers 32 distinct attack handlers for various network flooding techniques.

The second threat, dubbed “Monaco”, is an active cryptojacking operation written in Go 1.24.0.
This malware scans the internet for exposed SSH servers, routers, and IoT devices and attempts to brute-force access using hardcoded credentials such as “root” and “admin”.
Upon successful compromise, Monaco deploys Monero cryptocurrency miners to generate revenue using compromised devices as free computing power.
The Strategic Shift To Network Devices
The rise of CondiBot and Monaco aligns with a broader escalation in attacks against network technology. The 2025 Verizon Data Breach Investigation Report highlighted an 8x increase in exploitation of vulnerabilities in network devices.
Furthermore, Google Threat Intelligence reported that nearly a quarter of all zero-day vulnerabilities exploited in 2025 specifically targeted network and security appliances.
| Specification | CondiBot Variant (DDoS Botnet) | “Monaco” Variant (SSH Scanner & Crypto Miner) |
|---|---|---|
| Malware Family | Mirai derivative (DDoS executor) | Cryptominer |
| Filename | executor | executor |
| Language/Compiler | C (statically linked, stripped) | Go 1.24.0 (built 2025-02-11) |
| File Type | ELF 64-bit x86_64, statically linked, stripped | ELF 64-bit LSB executable, x86-64, statically linked |
As threat actors continue to weaponize network infrastructure, eclypsium organizations must look beyond traditional endpoint security.
Addressing these blind spots requires specialized detection capabilities that monitor firmware and anomalous behavior in network edge equipment.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.