Cybersecuritynews New CondiBot Variant and Monaco Miner Target Network Devices
Article Content
- •CondiBot and Monaco miner are targeting network devices like routers and firewalls.
- •Exploitation of network infrastructure has increased eight-fold in recent years.
- •Attackers include both nation-state actors and financially motivated criminals.
A new variant of CondiBot and the Monaco cryptominer are actively targeting network devices, including routers and firewalls, as attackers shift their focus to enterprise infrastructure. This trend has been noted in research showing an eight-fold increase in the exploitation of such devices over recent years. The attacks are attributed to a range of actors, from nation-state groups to financially motivated criminals. The CondiBot variant exploits vulnerabilities in network devices, allowing for initial access and long-term persistence within enterprise environments. The Monaco miner is also being deployed to leverage compromised devices for cryptomining activities. Organizations relying on network infrastructure are particularly vulnerable, as these devices are integral to their operations. Current mitigation strategies are not specified, indicating a pressing need for heightened security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CondiBot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…