www.darkreading.com 8/17/2026, 4:31:53 PM · external

New Evooo1Bot Linux malware blends Mirai with spyware, proxy tools

New Evooo1Bot Linux malware blends Mirai with spyware, proxy tools
Developing story malware 3 articles tracked
Evooo1Bot Linux botnet hijacks edge devices as SOCKS5 proxies
CyberSIXT Evidence Panel
Primary Source fortinet.com

THE article discusses the Evooo1Bot, a new Linux botnet that extends the capabilities of the well-known Mirai botnet by integrating multiple malicious functions beyond Distributed Denial of Service (DDoS) attacks. Discovered by Fortiguard Labs, Evooo1Bot targets various Internet-facing devices, exploiting vulnerabilities dating back to 2007.

It includes features like encrypted C2 communications, SSH brute-force attacks, a SOCKS relay for traffic routing, credential theft, and an arsenal of exploits for various vulnerabilities. Evooo1Bot's advanced capabilities allow attackers to leverage compromised devices as proxies to conceal their origin and gain further access into networks, making it a sophisticated threat.

Security measures recommended include patching vulnerable devices, monitoring for unauthorized activities, and maintaining vigilant defense strategies against evolving threats.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline