logo

New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots

ID: a4880528-0966-5ac5-8416-ec625d91d17c

STIX ID: report--a4880528-0966-5ac5-8416-ec625d91d17c

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Security researchers identified two new malware families—CondiBot (a Mirai-based DDoS botnet) and Monaco (an SSH brute-forcer and Monero miner)—that compromise Linux-based routers, IoT devices, and enterprise network equipment using multiple file-transfer methods, credential brute-force, and persistence techniques (disabling reboots, watchdog manipulation). The report highlights active exploitation risks to network infrastructure, minimal yet actionable indicators ("QTXBOT", "/bin/sora"), and recommends rapid patching, strong SSH credentials, and firmware integrity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.