Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a [

A new Mirai-based botnet, dubbed Evooo1Bot, has been observed targeting Linux-based routers and IoT devices since July 2026. The botnet, disclosed by Fortinet's FortiGuard Labs in mid-August, is designed for distributed denial-of-service (DDoS) attacks, credential theft, and establishing criminal proxy services.
Evooo1Bot incorporates the DDoS engine from the publicly leaked Mirai source code but significantly expands its capabilities. Key enhancements include encrypted command-and-control (C2) communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module. The botnet also features an integrated exploit arsenal targeting 18 known vulnerabilities, some dating back to 2007.
The targeted vulnerabilities include CVE-2007-3010 (Alcatel OmniPCX Enterprise), CVE-2016-6277 (NETGEAR Multiple Routers), CVE-2018-14558 (Tenda AC7, AC9, AC10 Routers), CVE-2019-14931 (Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU devices), CVE-2020-10987 (Tenda AC1900 Router AC15 Model), CVE-2021-46422 (Telesquare SDT-CW3B1), CVE-2022-37055 (D-Link Routers), CVE-2024-29269 (Telesquare TLR-2005KSH), CVE-2025-10123 (D-Link DIR-823X), and CVE-2025-55583 (D-Link DIR-868L B1 router). This broad targeting suggests an opportunistic approach by the operators, scanning for any unpatched devices.
Initial access is gained either through exploiting one of these vulnerabilities or via brute-forcing SSH credentials. Upon successful compromise, the bot executes a loader script that clears the Bash history to remove forensic evidence before downloading an architecture-appropriate binary from an external server.
A distinguishing feature of Evooo1Bot is its SOCKS5 proxy module. This module allows compromised devices to act as network relays, enabling attackers to obscure their traffic, bypass geographic restrictions, or gain access to internal networks. The module supports two modes: a direct mode, which opens a SOCKS5 listener on the infected host (default TCP port 1080), and a reverse relay mode, where the bot establishes an outbound encrypted connection to an operator-specified relay server. This functionality can be used by the operators themselves or monetized by selling access to other criminals.
The botnet communicates exclusively over port 443, a deliberate choice to blend malicious traffic with legitimate HTTPS flows at network perimeters. Beyond the proxy capabilities, Evooo1Bot includes a credential sniffer that intercepts HTTP Basic Auth and Cookie headers in transit, allowing operators to capture authentication credentials without additional effort.
The C2 communication is encrypted using AES-256-CTR, ChaCha20, and XOR-based key derivation, and the malware employs multiple layers of string obfuscation. The botnet also features a comprehensive 28-command remote administration interface, supporting file upload and download, interactive shell access, persistence installation, binary updates, and various DDoS attack types (DNS, TCP, UDP, HTTP exploit dispatcher).
The advanced capabilities of Evooo1Bot, particularly its encrypted C2 communications, sophisticated obfuscation, and integrated proxy module, elevate it beyond the typical technical baseline of Mirai-derived malware. Organizations are advised to patch devices against the listed CVEs and ensure that edge hardware does not use default SSH credentials to mitigate the risk of compromise.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.