LIVE · cybersecurity feed
Live wire
malware

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

zeroday.news ·

A new Linux botnet, dubbed "Evooo1Bot," has been identified as actively exploiting vulnerabilities in internet-facing edge devices since July 2026. The botnet, named after a hardcoded string found in its binaries, is a sophisticated variant based on the publicly leaked source code of the Mirai botnet.

Researchers at Fortinet's FortiGuard Labs, led by Taiwan-based security researcher Yi Ping (Cara) Lin, published an analysis of Evooo1Bot on August 13. Their discovery followed observations of exploitation attempts targeting a range of vulnerabilities, with all payload callbacks pointing to a single loader URL: 91.92.40[.]118/wget.sh.

The botnet leverages the distributed denial-of-service (DDoS) engine from the original Mirai source code, which was leaked in September 2016. However, Evooo1Bot's developers have significantly enhanced its capabilities beyond typical Mirai-derived malware.

Key features of Evooo1Bot include encrypted command-and-control (C2) communications, a 28-command remote administration interface, and multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation. It also incorporates an SSH brute-force scanner, a credential sniffer, and an integrated exploit arsenal.

One of the most significant additions is a reverse SOCKS relay module. This module transforms compromised edge devices into persistent proxies, allowing attackers to mask their true origin, pivot into internal networks, and conduct further operations through the victim's infrastructure.

Evooo1Bot's exploit arsenal targets numerous known vulnerabilities across various device types. These include CVE-2007-3010 in Alcatel OmniPCX Enterprise, CVE-2016-6277 in NETGEAR routers, and CVE-2018-14558 in Tenda AC7, AC9, and AC10 routers.

Further vulnerabilities exploited include CVE-2019-14931 in Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU devices, CVE-2020-10987 in the Tenda AC1900 Router AC15 model, and CVE-2021-46422 in Telesquare SDT-CW3B1. More recent targets include CVE-2022-37055 in D-Link routers, CVE-2024-29269 in Telesquare TLR-2005KSH, CVE-2025-10123 in D-Link DIR-823X, and CVE-2025-55583 in the D-Link DIR-868L B1 router.

The breadth of these targeted vulnerabilities, spanning from older issues to those identified in 2025, indicates a broad and active campaign against diverse networking equipment, IoT devices, and enterprise applications across various regions.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and