THE Evooo1Bot is a new Linux botnet based on Mirai, discovered by Fortinet's FortiGuard Labs. Active since July 2026, it targets routers and IoT devices for DDoS attacks, credential theft, and criminal proxy services. The botnet extends Mirai's capabilities by adding encrypted command-and-control communication, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module. It exploits 18 known CVEs to gain access, primarily communicating over port 443 to evade detection.
The Evooo1Bot's proxy capabilities allow it to disguise malicious traffic or sell access to compromised devices. It also includes a sophisticated remote administration toolkit for various commands and functions, enhancing its functionality beyond typical botnet features.