logo

New CondiBot Variant and ‘Monaco’ Cryptominer Expand Threats to Network Devices

ID: 65c648b2-2518-5c6e-b872-3082eec932e0

STIX ID: report--65c648b2-2518-5c6e-b872-3082eec932e0

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Eclypsium researchers identified two previously undocumented Linux-targeting malware strains: a new CondiBot DDoS botnet variant (internal identifier “QTXBOT”) and a Go-based cryptominer called “Monaco” that brute-forces SSH and exfiltrates credentials to a C2 on Alibaba Cloud Singapore. Both are compiled for multiple architectures (ARM, MIPS, x86/x86_64, ARM64) enabling wide reach across routers, IoT devices, and servers; CondiBot employs layered delivery (wget/curl/tftp/ftpget), persistence (disabling reboot utilities, watchdog manipulation), and process-killing of competitors, while Monaco performs credential theft and stealth mining. The report warns that financially motivated actors are increasingly targeting network infrastructure and recommends patching, credential hygiene, access restriction, and monitoring for unusual CPU/activity on network-facing devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.