A new Linux botnet, dubbed "Evooo1Bot," has been identified as actively exploiting vulnerabilities in internet-facing edge devices since July 2026. The botnet, named after a hardcoded string found in its binaries, is a sophisticated variant based on the publicly leaked source code of the Mirai botnet.
Researchers at Fortinet's FortiGuard Labs, led by Taiwan-based security researcher Yi Ping (Cara) Lin, published an analysis of Evooo1Bot on August 13. Their discovery followed observations of exploitation attempts targeting a range of vulnerabilities, with all payload callbacks pointing to a single loader URL: 91.92.40[.]118/wget.sh.
The botnet leverages the distributed denial-of-service (DDoS) engine from the original Mirai source code, which was leaked in September 2016. However, Evooo1Bot's developers have significantly enhanced its capabilities beyond typical Mirai-derived malware.
Key features of Evooo1Bot include encrypted command-and-control (C2) communications, a 28-command remote administration interface, and multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation. It also incorporates an SSH brute-force scanner, a credential sniffer, and an integrated exploit arsenal.
One of the most significant additions is a reverse SOCKS relay module. This module transforms compromised edge devices into persistent proxies, allowing attackers to mask their true origin, pivot into internal networks, and conduct further operations through the victim's infrastructure.
Evooo1Bot's exploit arsenal targets numerous known vulnerabilities across various device types. These include CVE-2007-3010 in Alcatel OmniPCX Enterprise, CVE-2016-6277 in NETGEAR routers, and CVE-2018-14558 in Tenda AC7, AC9, and AC10 routers.
Further vulnerabilities exploited include CVE-2019-14931 in Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU devices, CVE-2020-10987 in the Tenda AC1900 Router AC15 model, and CVE-2021-46422 in Telesquare SDT-CW3B1. More recent targets include CVE-2022-37055 in D-Link routers, CVE-2024-29269 in Telesquare TLR-2005KSH, CVE-2025-10123 in D-Link DIR-823X, and CVE-2025-55583 in the D-Link DIR-868L B1 router.
The breadth of these targeted vulnerabilities, spanning from older issues to those identified in 2025, indicates a broad and active campaign against diverse networking equipment, IoT devices, and enterprise applications across various regions.






