Condi is a Mirai-based botnet malware family used for distributed denial-of-service attacks and advertised through the Telegram-based Condi Network DDoS-as-a-service operation. It primarily compromises Linux-based routers and other IoT devices, with payloads supporting multiple processor architectures. Its source code became publicly available in 2023, allowing independent operators to develop and deploy derivatives; Condi-related code does not establish attribution to the original operator.
Condi propagates by scanning public IP addresses for exposed HTTP services and exploiting vulnerable devices. A principal infection vector is CVE-2023-1389, an unauthenticated command-injection vulnerability in TP-Link Archer AX21 routers. Exploitation downloads and executes shell scripts that retrieve architecture-specific bot binaries. Condi has also been deployed through exploitation of the GeoServer remote code execution vulnerability CVE-2024-36401. Attempts to distribute Condi-like payloads through CVE-2023-33538 in older TP-Link routers were observed, but the analyzed exploit attempts were unsuccessful.
The malware communicates with command-and-control infrastructure using a modified Mirai binary protocol and supports multiple TCP and UDP flooding methods, including SYN, ACK, and Valve Source Engine attacks. Operators can check bot activity, terminate bots, update distributed binaries, and start an embedded HTTP server on infected devices to serve additional malware. Condi aggressively terminates selected processes, including competing botnet processes, to retain control and hinder detection. Some process-killing logic is flawed and can disrupt legitimate device operation. It also deletes system utilities used for rebooting or shutting down devices to prolong infection, although the analyzed malware does not survive a system reboot. Condi campaigns have used cloud-hosted services for payload distribution and command-and-control communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Condi DDoS botnet "continues to exploit CVE-2023-1389 to gain control of devices and execute its malicious activities." The report identifies the affected product as TP-Link Archer AX21.
GeoServer의 원격 코드 실행 취약점(CVE-2024-36401)이 공개된 이후 최근까지도 해당 취약점을 악용해 악성코드를 설치하는 사례들이 확인되고 있다.
The attacks, in this case, attempt to deploy a Mirai-like botnet malware, with the source code featuring numerous references to the string "Condi." | Unit 42 said it detected active, automated scans and probes attempting to exploit CVE-2023-33538 (CVSS score: 8.8), a command injection vulnerability impacting EoL TP-Link wireless routers, albeit using a flawed approach that doesn't result in a successful compromise.
The Broadside malware infects TBK DVR devices impacted by CVE-2024-3721, an OS command injection flaw that can be exploited remotely for arbitrary code execution.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
sends a hardcoded exploitation request... to download and execute a remote shell script at hxxp://cdn2[.]duc3k[.]com/t... The remote shell script is typical of Mirai-based loaders that try to download and execute binaries of each architecture in turn
it embeds a simple scanner modified from Mirai’s original Telnet scanner to scan for any public IPs with open ports 80 or 8080... We found source code for an older version of Condi that scans for devices with an open Android Debug Bridge port (TCP/5555)
The arm7 binary also starts an HTTP server on the infected device using a port randomly chosen between 1024 and 65535. Once active, this server delivers fresh malware copies to other devices that connect to it, spreading the infection further without requiring any additional input from the attacker.
The binary protocol used by Condi to communicate with the C2 server is a modified version of that initially implemented in Mirai.
Once it receives the command used to start the webserver, this malware downloads bot binaries... After that, it starts a basic HTTP server on a random port number above 1024 to host these binaries.
The binary protocol used by Condi to communicate with the C2 server is a modified version of that initially implemented in Mirai.
it also prevents infections from other botnets by attempting to terminate their processes... kills any processes with matching names... kills any processes with binary filenames containing the following extensions commonly used by other botnets
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Condi is referenced as an IoT botnet whose malware is similar to the observed arm7 Mirai variant. The binary acts as a command-driven bot and distribution node, connecting to C2 infrastructure, executing commands, updating itself, and serving malware binaries to spread across devices.
A Mirai-like botnet malware referenced in source code strings. The malware can update itself and act as a web server to spread infection to other connected devices.
Mirai-based IoT botnet malware deployed to vulnerable TP-Link routers after exploitation of CVE-2023-33538. Once executed, it connects to a C2 server, sends heartbeats, supports self-updates, starts an HTTP server on the infected device, and helps propagate malware copies to additional devices.
An IoT botnet malware family referenced as closely matching the downloaded arm7 sample. The sample contains multiple 'condi' strings and exhibits Mirai-like botnet behavior including C2 command handling, self-update across multiple architectures, and HTTP-based propagation support.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.