logo

New Mirai Variant and “Monaco” Miner Targeting Linux Devices

ID: e26b7224-e938-58f1-86b8-48c2fcf105ea

STIX ID: report--e26b7224-e938-58f1-86b8-48c2fcf105ea

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Eclypsium researchers identified two previously undocumented Linux threats: CondiBot, a vendor-agnostic, multi-architecture botnet variant designed to conscript devices for large-scale DDoS; and "Monaco", an automated SSH brute-forcing cryptojacking operation that scans ~3.6 billion IPs, uses a 50+ hardcoded password list, installs to /tmp/monaco, kills competing miners, and deploys XMRig (using default token "mySecret"); Monaco shows infrastructure ties to Alibaba Cloud Singapore and indicators suggesting a Chinese-speaking actor. Recommended mitigations include enforcing strong passwords, disabling or restricting SSH, monitoring CPU/resource spikes, and segmenting IoT/network devices from critical systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.