Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.

A new variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, according to researchers. This Linux-based malware targets routers and other devices from manufacturers including Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare. Unpatched security flaws in these devices are being leveraged by Evooo1Bot for propagation and malicious activities.
Evooo1Bot introduces several advanced capabilities that distinguish it from typical Mirai derivatives. It incorporates encrypted communications with its command-and-control servers, enhancing its operational stealth. The malware also includes a scanner designed to detect Secure Shell (SSH) code, with a mechanism to bypass devices configured as honeypots to avoid detection. Additionally, it features a "sniffer" that searches for default access credentials that have not been changed from their factory settings.
Beyond the standard distributed denial-of-service (DDoS) functions commonly associated with Mirai, Evooo1Bot's most significant new feature is its abuse of the SOCKS protocol. This allows compromised routers, firewalls, IP cameras, and other edge devices to be transformed into persistent proxies. This capability enables attackers to mask their true origin, pivot into internal networks, and conduct subsequent operations using the victim's infrastructure.
Telemetry data indicates that Evooo1Bot activity is concentrated across multiple regions globally, including North America, South America, Europe, India, China, and Japan. While the exact number of compromised devices worldwide has not been specified, the widespread geographical distribution suggests a broad impact.
The source code for the original Mirai botnet was released publicly in 2016, leading to the development of numerous variants over the past decade. These variants have frequently drawn the attention of law enforcement and cybersecurity experts. For instance, in March, law enforcement agencies from the U.S., Canada, and Germany targeted Mirai descendants such as Aisuru and KimWolf. A Canadian individual was subsequently charged in May in connection with operating KimWolf.



U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [

The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Phishers find a new use for invisible Unicode tag characters