In May 2023, a new DDoS-as-a-Service botnet named “Condi” emerged, exploiting a vulnerability in TP-Link Archer AX21 (AX1800) Wi-Fi routers to create an army of bots and conduct attacks.
See also: The city of Fayetteville, Arkansas, faces a debilitating cyberattack

The AX1800 is a popular dual-band (2.4 GHz + 5 GHz) Linux-based Wi-Fi 6 router with 1.8 Gbps bandwidth, mainly used by home users, small offices, shops, cafes, etc.
The Condi malware aims to recruit new devices to create a powerful DDoS (distributed denial of service) botnet, which can be rented to launch attacks on websites and services.
Additionally, the threat actors behind the Condi malware are selling the malware's source code. This is an unusually aggressive monetization method intended to lead to numerous project forks with different features.

A new report from Fortinet published today explains that the Condi malware targets CVE-2023-1389, a high-severity, unauthorized command injection and remote code execution vulnerability in the router's web management interface API.
See also: Russian hackers APT28 breached email servers of Ukrainian organizations
ZDI discovered the flaw and reported it to the network equipment vendor in January 2023, with TP-Link releasing a security update 1.1.4 Build 20230219 in March. Condi is the second DDoS botnet to target this vulnerability, after Mirai previously exploited it in late April.
To combat overlapping attacks, Condi has a mechanism that attempts to kill any processes belonging to known competing botnets. At the same time, it also stops older versions of itself. Since Condi does not have a persistence mechanism to survive between device reboots, its creators decided to equip it with a wiper for the following files, which prevents devices from being shut down or rebooted.
- /usr/sbin/reboot
- /usr/bin/reboot
- /usr/sbin/shutdown
- /usr/bin/shutdown
- /usr/sbin/poweroff
- /usr/bin/poweroff
- /usr/sbin/halt
- /usr/bin/halt
To spread to vulnerable TP-Link routers, the malware looks for public IPs with open ports 80 or 8080 and sends a hardcoded exploitation request to download and execute a remote shell script, infecting the new device.

Fortinet says that while the samples it analyzed contained a scanner for CVE-2023-1389, it has also observed other Condi samples that use different flaws to spread - so their authors or handlers may be experimenting on this front.
Additionally, analysts found samples using a shell script with ADB (Android Debug Bridge) source, potentially indicating that the botnet is spreading via devices with an open ADB port (TCP/5555).
In all likelihood, this is the direct result of multiple threat actors who have purchased Condi's source code and are adapting its attacks as they see fit.
Regarding Condi's DDoS attack capabilities, the malware supports various UDP flood and UDP methods similar to those of Mirai.
See also: Manchester University: Hackers threaten data leak
Older samples also contained HTTP attack methods - however, these appear to have been removed from the latest version of the malware.
Owners of the Archer AX21 AX1800 Dual-Band Wi-Fi 6 Router can get the latest firmware update for their device 's hardware version from the TP-Link download center
Signs of an infected TP-Link router include overheating of the device, network outages, unexplained changes to the device's network settings, and resetting the administrator password.
Information source: bleepingcomputer.com
