Eclypsium unearths stealth miners that turn routers into cash cows
Two new malware strains slipped past every radar until Eclypsium caught them quietly converting Linux boxes into zombie mints and DDoS artillery. The first sample, dubbed CondiBot, popped up on 6 March; the second, Monaco, arrived the same day. Both signal a pivot: crooks now treat firmware like an ATM.
CondiBot is a Mirai grandchild written in C. Once dropped on a router or camera, it neuters reboot commands, phones home to a command server, then waits for orders to flood targets with junk traffic. Fortinet boxes are on the menu, but any embedded Linux device will do. The binary cycles through half-a-dozen download paths until one sticks; after that, the owner loses control of the power cord.

Monaco turns brute-force success into coin
Monaco, coded in Go, skips the DDoS circus and goes straight for the wallet. It scans the entire public IPv4 space on port 22, hammering admin, ubuntu, root and other lazy passwords until it cracks an SSH gate. The reward: a silent Monero miner that purges rival parasites and ships hashes to Alibaba Cloud Singapore (8.222.206.6). Chinese-language artifacts litter the build, but attribution remains a guessing game behind a rented VPS.
Eclypsium’s telemetry shows both families spreading in the shadow of geopolitical noise. While analysts chase state-sponsored implants, opportunistic miners fill the vacuum, turning thermostats and Wi-Fi extenders into fractional revenue streams. The lesson: if it runs Linux and faces the internet, it’s already on someone’s candidate list.
Google’s Threat Analysis Group reached the same conclusion last month, warning that initial access brokers now shop for firmware footholds to pivot inside corporate nets. World Cup fever, mid-term elections, AI hype—each event is a smoke screen for a quieter heist happening inside the closet where the router blinks.
Patch your firmware or finance someone else’s crypto wallet. The clock on the closet wall is ticking louder every day.
