New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
ID: 48e951b8-4aa2-52e3-8815-d71fc619d939
STIX ID: report--48e951b8-4aa2-52e3-8815-d71fc619d939
Feed Name: Infosecurity Magazine (News)
Researchers at Fortinet’s FortiGuard Labs describe ‘Evooo1Bot’, a Mirai-derived modular Linux botnet observed exploiting numerous known vulnerabilities in routers and edge devices and deploying a common loader (91.92.40.118/wget.sh); the malware reuses Mirai’s DDoS engine but adds encrypted C2, an SSH brute-force scanner, a reverse SOCKS relay (enabling proxying/pivoting), credential stealing and an integrated exploit arsenal, with active exploitation observed since July 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
