Multi-Functional Linux Botnet “Evooo1Bot”
ID: e0387d99-cd8e-55be-a0c2-4882f85b123d
STIX ID: report--e0387d99-cd8e-55be-a0c2-4882f85b123d
Feed Name: Fortinet Blog
Threat Score
FortiGuard Labs details Evooo1Bot, a Mirai-derived Linux botnet active since July 2026 that extends Mirai with encrypted C2, SSH brute-forcing, a SOCKS5 reverse relay, credential sniffing, a modular CVE exploit dispatcher, persistence mechanisms, and a 28-command remote administration interface; telemetry and IOCs (91.92.40.118 and file hashes) show active exploitation of numerous IoT and network device vulnerabilities, and Fortinet detections and mitigations are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
