securityaffairs.com 8/18/2026, 8:01:48 AM · external

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Developing story malware 4 articles tracked
Evooo1Bot Mirai-based Linux botnet targets edge devices
CyberSIXT Evidence Panel
Primary Source fortinet.com

THE Evooo1Bot is a new Linux botnet based on Mirai, discovered by Fortinet's FortiGuard Labs. Active since July 2026, it targets routers and IoT devices for DDoS attacks, credential theft, and criminal proxy services. The botnet extends Mirai's capabilities by adding encrypted command-and-control communication, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module. It exploits 18 known CVEs to gain access, primarily communicating over port 443 to evade detection.

The Evooo1Bot's proxy capabilities allow it to disguise malicious traffic or sell access to compromised devices. It also includes a sophisticated remote administration toolkit for various commands and functions, enhancing its functionality beyond typical botnet features.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline