New CondiBot Variant and ‘Monaco’ Cryptominer Expand Threats to Network Devices
ID: 65c648b2-2518-5c6e-b872-3082eec932e0
STIX ID: report--65c648b2-2518-5c6e-b872-3082eec932e0
Feed Name: cybersecurityNews.com
Eclypsium researchers identified two previously undocumented Linux-targeting malware strains: a new CondiBot DDoS botnet variant (internal identifier “QTXBOT”) and a Go-based cryptominer called “Monaco” that brute-forces SSH and exfiltrates credentials to a C2 on Alibaba Cloud Singapore. Both are compiled for multiple architectures (ARM, MIPS, x86/x86_64, ARM64) enabling wide reach across routers, IoT devices, and servers; CondiBot employs layered delivery (wget/curl/tftp/ftpget), persistence (disabling reboot utilities, watchdog manipulation), and process-killing of competitors, while Monaco performs credential theft and stealth mining. The report warns that financially motivated actors are increasingly targeting network infrastructure and recommends patching, credential hygiene, access restriction, and monitoring for unusual CPU/activity on network-facing devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
