New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
ID: 64922664-5e2c-503e-b8cf-296e3d134b62
STIX ID: report--64922664-5e2c-503e-b8cf-296e3d134b62
Feed Name: Security Affairs
**Evooo1Bot**, a Mirai-based Linux botnet active since July 2026 and disclosed by FortiGuard Labs, compromises routers and IoT devices using a wide exploit arsenal (18 CVEs) and SSH brute force to deliver a Mirai-derived DDoS engine plus advanced features such as encrypted C2, credential sniffing, and a SOCKS5 proxy module that enables monetized or anonymized traffic relay; it communicates over port 443, clears bash history on compromise, and supports a 28-command remote administration interface for payload management and exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
