New CondiBot Variant and ‘Monaco’ Miner Target More Network Devices
ID: db180ba2-2e02-51bc-bfaf-274efe3443e6
STIX ID: report--db180ba2-2e02-51bc-bfaf-274efe3443e6
Feed Name: GBHackers
This report details Eclypsium's discovery of a new CondiBot variant and a Go-based 'Monaco' SSH scanner/Monero miner that target a wide range of architectures and network/edge devices. The malware uses multiple download methods, disables reboots and watchdogs, kills competing bots, brute-forces SSH with a large credential list, and reports compromised credentials and mining traffic to identified C2 infrastructure (e.g., 65.222.202.53 and 8.222.206.6); the findings underscore growing exploitation of routers, VPNs, and firewalls and recommend treating network devices as critical endpoints for monitoring and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
