LIVE · cybersecurity feed
Live wire
malware

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a [

zeroday.news ·

A new Mirai-based botnet, dubbed Evooo1Bot, has been observed targeting Linux-based routers and IoT devices since July 2026. The botnet, disclosed by Fortinet's FortiGuard Labs in mid-August, is designed for distributed denial-of-service (DDoS) attacks, credential theft, and establishing criminal proxy services.

Evooo1Bot incorporates the DDoS engine from the publicly leaked Mirai source code but significantly expands its capabilities. Key enhancements include encrypted command-and-control (C2) communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module. The botnet also features an integrated exploit arsenal targeting 18 known vulnerabilities, some dating back to 2007.

The targeted vulnerabilities include CVE-2007-3010 (Alcatel OmniPCX Enterprise), CVE-2016-6277 (NETGEAR Multiple Routers), CVE-2018-14558 (Tenda AC7, AC9, AC10 Routers), CVE-2019-14931 (Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU devices), CVE-2020-10987 (Tenda AC1900 Router AC15 Model), CVE-2021-46422 (Telesquare SDT-CW3B1), CVE-2022-37055 (D-Link Routers), CVE-2024-29269 (Telesquare TLR-2005KSH), CVE-2025-10123 (D-Link DIR-823X), and CVE-2025-55583 (D-Link DIR-868L B1 router). This broad targeting suggests an opportunistic approach by the operators, scanning for any unpatched devices.

Initial access is gained either through exploiting one of these vulnerabilities or via brute-forcing SSH credentials. Upon successful compromise, the bot executes a loader script that clears the Bash history to remove forensic evidence before downloading an architecture-appropriate binary from an external server.

A distinguishing feature of Evooo1Bot is its SOCKS5 proxy module. This module allows compromised devices to act as network relays, enabling attackers to obscure their traffic, bypass geographic restrictions, or gain access to internal networks. The module supports two modes: a direct mode, which opens a SOCKS5 listener on the infected host (default TCP port 1080), and a reverse relay mode, where the bot establishes an outbound encrypted connection to an operator-specified relay server. This functionality can be used by the operators themselves or monetized by selling access to other criminals.

The botnet communicates exclusively over port 443, a deliberate choice to blend malicious traffic with legitimate HTTPS flows at network perimeters. Beyond the proxy capabilities, Evooo1Bot includes a credential sniffer that intercepts HTTP Basic Auth and Cookie headers in transit, allowing operators to capture authentication credentials without additional effort.

The C2 communication is encrypted using AES-256-CTR, ChaCha20, and XOR-based key derivation, and the malware employs multiple layers of string obfuscation. The botnet also features a comprehensive 28-command remote administration interface, supporting file upload and download, interactive shell access, persistence installation, binary updates, and various DDoS attack types (DNS, TCP, UDP, HTTP exploit dispatcher).

The advanced capabilities of Evooo1Bot, particularly its encrypted C2 communications, sophisticated obfuscation, and integrated proxy module, elevate it beyond the typical technical baseline of Mirai-derived malware. Organizations are advised to patch devices against the listed CVEs and ensure that edge hardware does not use default SSH credentials to mitigate the risk of compromise.

malwareddosai
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

security

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume

security

Microsoft tests faster Windows File Explorer, new context menu

Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]

breachcritical

LLMs and Contextual Integrity

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this memory introdu

phishing

Heights Finance data breach: What customers need to know

Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.

ransomwarehigh

CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]