Skip to content
New CondiBot Variant and Monaco Miner Target Network Devices

New CondiBot Variant and Monaco Miner Target Network Devices

First seen 17 Mar 2026, 06:36 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 18, 2026 at 04:57 UTC
  • •CondiBot and Monaco miner are targeting network devices like routers and firewalls.
  • •Exploitation of network infrastructure has increased eight-fold in recent years.
  • •Attackers include both nation-state actors and financially motivated criminals.

A new variant of CondiBot and the Monaco cryptominer are actively targeting network devices, including routers and firewalls, as attackers shift their focus to enterprise infrastructure. This trend has been noted in research showing an eight-fold increase in the exploitation of such devices over recent years. The attacks are attributed to a range of actors, from nation-state groups to financially motivated criminals. The CondiBot variant exploits vulnerabilities in network devices, allowing for initial access and long-term persistence within enterprise environments. The Monaco miner is also being deployed to leverage compromised devices for cryptomining activities. Organizations relying on network infrastructure are particularly vulnerable, as these devices are integral to their operations. Current mitigation strategies are not specified, indicating a pressing need for heightened security measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 206d ago How this analysis works

Timeline

2026-03-17
New CondiBot variant and Monaco miner reported targeting network devices.
Recent
Research indicates an eight-fold increase in network device exploitation.

More articles in this cluster (2)

Following this threat?

Track CondiBot in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed