Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New Mirai-Based Botnet Evooo1Bot Targets Linux Devices, Exploits 18 Known Vulnerabilities




A new Mirai-based botnet, dubbed Evooo1Bot, has been identified as a significant threat to organizations and individuals who rely on vulnerable devices and networks. This botnet hijacks routers and IoT devices to carry out DDoS attacks, credential theft, and criminal proxy services, and targets 18 known vulnerabilities. The Evooo1Bot malware stands out for its proxy module, which allows it to create a network of compromised devices and establish a persistent control channel with operators. The implications of this malware are significant, and highlight the need for organizations to prioritize patching vulnerable devices and using robust security measures to prevent exploitation.

  • The Evooo1Bot malware is a Mirai-based botnet that hijacks routers and IoT devices for DDoS attacks, credential theft, and criminal proxy services.
  • The botnet uses encrypted command-and-control communications, an SSH brute-force scanner, and a SOCKS5 proxy module, allowing it to blend into HTTPS flows.
  • The botnet targets 18 known CVEs, including some from 2007, to gain initial access to infected devices.
  • The malware features a proxy module that creates a network of compromised devices, allowing operators to obscure attack traffic and bypass geographic restrictions.
  • The botnet has encrypted C2 communications, multiple layers of string obfuscation, and a 28-command remote administration interface, making it a significant threat.
  • The Evooo1Bot malware highlights the need for organizations to patch vulnerable devices and use robust security measures to prevent exploitation.



  • The cybersecurity landscape has recently been shaken by the emergence of a new Mirai-based botnet, dubbed Evooo1Bot. This botnet has been identified as a Linux-based malware that hijacks routers and IoT devices to carry out Distributed Denial of Service (DDoS) attacks, credential theft, and criminal proxy services. Fortinet’s FortiGuard Labs has been tracking this botnet since mid-August 2026, and has revealed that it has been active since July 2026.

    The Evooo1Bot malware borrows the DDoS engine from the publicly leaked Mirai source code but adds several additional capabilities, including encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module. This allows the botnet to communicate exclusively over port 443, which is intentional as it blends into expected HTTPS flows at the network perimeter.

    According to FortiGuard Labs, the botnet targets 18 known CVEs, some of which date back to 2007. These vulnerabilities include CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583, and several others. The botnet uses these vulnerabilities to gain initial access to infected devices before running a loader script that clears Bash history to erase evidence of the intrusion.

    The Evooo1Bot malware stands out for its proxy module, which allows the botnet to create a network of compromised routers, cameras, and firewalls acting as SOCKS5 relays. This network of compromised devices can be used by the operators to obscure attack traffic, bypass geographic restrictions, or provide access to internal networks through already compromised machines. The proxy module also supports two operating modes, direct mode and reverse relay mode, which allow the botnet to establish a persistent control channel with operators.

    The Evooo1Bot malware also features encrypted C2 communications, multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation, as well as a 28-command remote administration interface. This places the botnet well beyond the technical baseline of conventional Mirai-derived malware.

    The implications of the Evooo1Bot malware are significant, as it highlights the need for organizations to prioritize the patching of vulnerable devices and the use of robust security measures to prevent exploitation. The botnet’s ability to create a network of compromised devices also underscores the importance of network segmentation and the use of intrusion detection systems to detect and respond to potential threats.

    In conclusion, the Evooo1Bot malware represents a significant threat to organizations and individuals who rely on vulnerable devices and networks. Its ability to exploit multiple known vulnerabilities and create a network of compromised devices makes it a formidable opponent in the fight against cyber threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-Mirai-Based-Botnet-Evooo1Bot-Targets-Linux-Devices-Exploits-18-Known-Vulnerabilities-ehn.shtml

  • https://securityaffairs.com/197434/malware/new-mirai-based-evooo1bot-botnet-targets-linux-devices.html


  • Published: Tue Aug 18 03:37:07 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us