logo

New Mirai variant adds stealth capabilities to notorious botnet code

ID: b03e9536-b6ee-5102-9862-5b2dbab91475

STIX ID: report--b03e9536-b6ee-5102-9862-5b2dbab91475

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

...
...

FortiGuard Labs researchers report a newly observed Mirai-derived Linux botnet named Evooo1Bot that has actively exploited unpatched vulnerabilities in various consumer and enterprise devices (Alcatel, D-Link, Netgear, Tenda, Mitsubishi Electric, Telesquare). Evooo1Bot extends Mirai functionality with encrypted C2, SSH scanning that avoids honeypots, credential-sniffing, and SOCKS proxying—allowing compromised edge devices to be used as persistent proxies for concealment and lateral action; activity has been observed across multiple continents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.