logo

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

ID: 64922664-5e2c-503e-b8cf-296e3d134b62

STIX ID: report--64922664-5e2c-503e-b8cf-296e3d134b62

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: Pierluigi Paganini

...
...

**Evooo1Bot**, a Mirai-based Linux botnet active since July 2026 and disclosed by FortiGuard Labs, compromises routers and IoT devices using a wide exploit arsenal (18 CVEs) and SSH brute force to deliver a Mirai-derived DDoS engine plus advanced features such as encrypted C2, credential sniffing, and a SOCKS5 proxy module that enables monetized or anonymized traffic relay; it communicates over port 443, clears bash history on compromise, and supports a 28-command remote administration interface for payload management and exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.