logo

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

ID: 48e951b8-4aa2-52e3-8815-d71fc619d939

STIX ID: report--48e951b8-4aa2-52e3-8815-d71fc619d939

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-08-14

Date Updated: 2026-08-14

...
...

Researchers at Fortinet’s FortiGuard Labs describe ‘Evooo1Bot’, a Mirai-derived modular Linux botnet observed exploiting numerous known vulnerabilities in routers and edge devices and deploying a common loader (91.92.40.118/wget.sh); the malware reuses Mirai’s DDoS engine but adds encrypted C2, an SSH brute-force scanner, a reverse SOCKS relay (enabling proxying/pivoting), credential stealing and an integrated exploit arsenal, with active exploitation observed since July 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.