LIVE · cybersecurity feed
Live wire
malware

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]

zeroday.news ·

A new Linux botnet, dubbed Evooo1Bot, has been observed targeting internet-facing gateway devices since at least July, transforming them into SOCKS5 traffic relay nodes. The modular malware, which is based on the Mirai source code, also possesses capabilities for credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks.

Researchers have identified that Evooo1Bot targets devices from several manufacturers, including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, by exploiting known vulnerabilities. The botnet's geographical spread is currently under analysis.

While Evooo1Bot reuses Mirai's DDoS engine, it significantly expands upon the original framework. Its enhanced features include encrypted command-and-control (C2) communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal. These exploits target a range of known vulnerabilities in various products.

Newer builds of the malware incorporate a separate vulnerability-exploitation module designed to target Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, some of these embedded exploits are reportedly not correctly implemented, leading to failed exploitation attempts.

Upon successful exploitation, a script downloads one of 12 malware builds tailored to the host's CPU architecture, then clears Bash history to remove traces of the attack. Evooo1Bot utilizes encrypted C2 communications over port 443 and conducts extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before executing on an infected device.

Persistence is established through various methods, including systemd, SysV init, shell profiles, and rc.local. A cron job is also set up to attempt re-downloading the payload every five minutes. The malware provides operators with an interactive shell for direct control over compromised systems and supports file transfers.

The credential sniffer module monitors `/proc/net/tcp` to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports both direct listening and reverse-relay modes, enabling attackers to mask malicious traffic, bypass geographic restrictions, or potentially gain access to internal networks via compromised systems. Proxying sessions run independently, and multiple can be opened concurrently, which could allow for monetization through residential proxy services if the botnet expands.

The SSH scanner module employs 150 username and password combinations, primarily targeting enterprise accounts, and includes post-login checks to avoid honeypots. The DDoS module, inherited from Mirai, supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests.

To mitigate the risk of botnet infection, users are advised to keep IoT device firmware updated, replace default administrative credentials, disable remote access panels, and replace devices when vendor support for them ceases.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and