Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

A new Linux botnet, dubbed "Evooo1Bot," has been identified as actively exploiting vulnerabilities in internet-facing edge devices since July 2026. The botnet, named after a hardcoded string found in its binaries, is a sophisticated variant based on the publicly leaked source code of the Mirai botnet.
Researchers at Fortinet's FortiGuard Labs, led by Taiwan-based security researcher Yi Ping (Cara) Lin, published an analysis of Evooo1Bot on August 13. Their discovery followed observations of exploitation attempts targeting a range of vulnerabilities, with all payload callbacks pointing to a single loader URL: 91.92.40[.]118/wget.sh.
The botnet leverages the distributed denial-of-service (DDoS) engine from the original Mirai source code, which was leaked in September 2016. However, Evooo1Bot's developers have significantly enhanced its capabilities beyond typical Mirai-derived malware.
Key features of Evooo1Bot include encrypted command-and-control (C2) communications, a 28-command remote administration interface, and multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation. It also incorporates an SSH brute-force scanner, a credential sniffer, and an integrated exploit arsenal.
One of the most significant additions is a reverse SOCKS relay module. This module transforms compromised edge devices into persistent proxies, allowing attackers to mask their true origin, pivot into internal networks, and conduct further operations through the victim's infrastructure.
Evooo1Bot's exploit arsenal targets numerous known vulnerabilities across various device types. These include CVE-2007-3010 in Alcatel OmniPCX Enterprise, CVE-2016-6277 in NETGEAR routers, and CVE-2018-14558 in Tenda AC7, AC9, and AC10 routers.
Further vulnerabilities exploited include CVE-2019-14931 in Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU devices, CVE-2020-10987 in the Tenda AC1900 Router AC15 model, and CVE-2021-46422 in Telesquare SDT-CW3B1. More recent targets include CVE-2022-37055 in D-Link routers, CVE-2024-29269 in Telesquare TLR-2005KSH, CVE-2025-10123 in D-Link DIR-823X, and CVE-2025-55583 in the D-Link DIR-868L B1 router.
The breadth of these targeted vulnerabilities, spanning from older issues to those identified in 2025, indicates a broad and active campaign against diverse networking equipment, IoT devices, and enterprise applications across various regions.



Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

Daybreak program brings subsidized models, training, and support to under-resourced teams