New Malware Campaigns Turn Network Devices Into DDoS Nodes and Crypto-Mining Bots
On March 6, 2026, two new malware strains were identified, targeting network devices for distributed denial-of-service (DDoS) attacks and cryptocurrency mining. The strains, named CondiBot and Monaco, exploit routers, IoT devices, and enterprise network…
On March 6, 2026, two new malware strains were identified, targeting network devices for distributed denial-of-service (DDoS) attacks and cryptocurrency mining. The strains, named CondiBot and Monaco, exploit routers, IoT devices, and enterprise network equipment.
CondiBot: A DDoS botnet based on the Mirai framework. It infects Linux-based network devices, transforming them into nodes for flooding targeted systems. Monaco: An SSH scanner and crypto miner written in Go 1.24.0. It breaches servers and devices by brute-forcing weak SSH credentials, deploying Monero mining software.
Neither strain had been previously reported on major threat intelligence platforms, highlighting a significant gap in current detection capabilities.
CondiBot uses various file transfer utilities to deliver its payload to vulnerable Linux devices. Once installed, it disables reboot utilities to persist after system restarts. It then connects to a command-and-control server, awaiting attack commands. This variant includes a string labeled "QTXBOT," indicating a possible fork from previous versions.
The strains, named CondiBot and Monaco, exploit routers, IoT devices, and enterprise network equipment.
Monaco employs SSH brute-forcing to gain access to network devices, subsequently deploying cryptocurrency mining software. Both strains demonstrate a shift towards targeting network infrastructure, traditionally the domain of state-sponsored attackers, now exploited by financially motivated groups.
The 2025 Verizon Data Breach Investigation Report noted an eightfold increase in vulnerability exploits targeting network devices, with zero-day exploits becoming commonplace. Additionally, the Google Threat Intelligence Group found that nearly a quarter of zero-day vulnerabilities in 2025 targeted network systems.
Enforce strong, unique SSH credentials and disable default passwords on internet-facing devices. Implement firmware integrity monitoring on routers, firewalls, and IoT equipment. Apply security patches promptly, given the short timelines for exploits. Monitor for unusual outbound traffic and unexpected processes on network appliances.
These measures can help mitigate the risks posed by these new malware strains, ensuring robust network security against evolving threats.
Based on reporting by Cyber Security News.
