logo

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

ID: 7bd2bddc-f7d0-55e0-83d3-6bccdf1542a4

STIX ID: report--7bd2bddc-f7d0-55e0-83d3-6bccdf1542a4

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

Author: Elizabeth Montalbano

...
...

FortiGuard Labs identified a Mirai-derived Linux botnet named Evooo1Bot actively exploiting numerous known vulnerabilities in routers, cameras, and other edge devices to deploy a modular platform that combines DDoS capabilities with encrypted C2, SSH brute-force, credential theft, persistence mechanisms, and a reverse SOCKS proxy that can be used to pivot and conceal attacker activity; observed indicators include callbacks to 91.92.40.118/wget.sh and exploitation of multiple CVEs dating back to 2007. Defenders are advised to patch or replace exposed appliances, inspect for unauthorized cron/systemd/init changes, investigate unexpected SSH activity, and monitor for devices acting as SOCKS/proxy endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.