A new Linux botnet named 'Evooo1Bot,' derived from the Mirai malware, has been identified exploiting various vulnerabilities in edge devices. Discovered by Yi Ping (Cara) Lin from Fortinet, the botnet targets known weaknesses in devices from manufacturers like Alcatel, NETGEAR, and D-Link, among others.
Evooo1Bot enhances Mirai's capabilities by adding features like encrypted C2 communications, an SSH brute-force scanner, credential sniffers, and a reverse SOCKS relay, making it more sophisticated than typical Mirai variants. This botnet began actively targeting devices in July 2026, with all exploit payloads pointing to a common loader URL.