INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Linux Botnet Exploits Known Flaws to Turn Victims Into Proxies
| 2026-08-17 09:29 HIGH HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
The Evooo1Bot Linux botnet, a variant of the Mirai DDoS engine, has been targeting Internet-facing devices since at least July. This sophisticated malware exploits vulnerabilities as old as 2007 and recent flaws discovered last year, giving attackers a multifunctional platform for compromising and monetizing vulnerable Linux-based devices. The botnet's entry points include command injection and remote code execution bugs such as CVE-2007-3010 to CVE-2020-10987. With its reverse SOCKS relay module being the most significant advancement, Evooo1Bot can turn compromised edge devices into full attacker infrastructure, hiding their real location and providing a foothold for deeper network infiltration. This highlights how Mirai's leaked codebase continues to be a gift that keeps on giving for attackers, allowing them to evolve from relative novelties to sophisticated threats.
Technical Mitigations AI-generated
* Implement and regularly update software updates for Internet-facing devices to ensure they have the latest security patches, especially those related to known vulnerabilities such as CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, and CVE-2020-10987.
* Use secure protocols for communication with Internet-facing devices, such as encrypted SSH or HTTPS, and avoid using hardcoded strings like "evooo1" that can be exploited by attackers.
* Monitor device logs and system configurations to detect potential vulnerabilities or suspicious activity, and take prompt action if necessary to prevent exploitation.
* Implement a robust patch management process to ensure all affected systems are patched before allowing them to connect to the internet, and consider using a vulnerability scanning tool to identify unpatched devices.
* Use secure boot mechanisms for Linux-based devices to prevent attackers from installing malware or modifying system configurations without being detected.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
wg•••••.sh
se•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-10123CVE-2025-10123
CVE-2024-29269CVE-2024-29269
CVE-2022-29464CVE-2022-29464
CVE-2024-10914CVE-2024-10914
CVE-2024-4577CVE-2024-4577
CVE-2020-10987CVE-2020-10987
CVE-2019-14931CVE-2019-14931
CVE-2025-55583CVE-2025-55583
CVE-2016-6277CVE-2016-6277
CVE-2007-3010CVE-2007-3010
CVE-2025-1974CVE-2025-1974
CVE-2021-46422CVE-2021-46422
CVE-2021-36260CVE-2021-36260
CVE-2022-37055CVE-2022-37055
CVE-2022-26134CVE-2022-26134
CVE-2018-14558CVE-2018-14558
CVE-2022-30525CVE-2022-30525
CVE-2023-1389CVE-2023-1389
Target & Sectors
EUROPE
EUROPE
Incident Timeline
September 2016
Threat actors used a publicly leaked version of Evooo1Bot to target Edge devices, exploiting known flaws in the device's software.
Click on any entity below to view its context and source!
tactic
Ddos
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless
modern malware variants
that continue to reuse Mirai's DDoS engine today.
attribution
Hack Forums
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless
modern malware variants
that continue to reuse Mirai's DDoS engine today.
attribution
FBI
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless
modern malware variants
that continue to reuse Mirai's DDoS engine today.
2025/08/17
The researchers discovered the hardcoded string "evooo1" in every binary of an Evooo1Bot Linux botnet, exploiting known vulnerabilities as old as 2007.
Click on any entity below to view its context and source!
tactic
Botnet
The researchers named the botnet — which exploits a host of vulnerabilities as old as 2007 as well as flaws discovered just last year — after finding the hardcoded string "evooo1" in every binary.
July 2026
Evooo1Bot uses the Mirai botnet's distributed denial-of-service engine to launch DDoS attacks.
Click on any entity below to view its context and source!
tactic
Botnet
Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware.
Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.
Evooo1Bot, A Sophisticated Mirai-Class Botnet
Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from the Mirai source code.
tactic
T1584.005 - Botnet
Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.
Evooo1Bot, A Sophisticated Mirai-Class Botnet
Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from the Mirai source code.
tactic
Ddos
Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.
Evooo1Bot, A Sophisticated Mirai-Class Botnet
Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from the Mirai source code.
organisation
CVE-2007-3010
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
CVE-2018-14558
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
CVE-2022-37055
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
infrastructure
91.92.40
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
Mitsubishi Electric Europe B.V. ME-RTU
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
INEA ME-RTU
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
Command
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
CPU
Some of the security flaws weaponized by the botnet are below -
CVE-2007-3010
- Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
CVE-2016-6277
- NETGEAR Multiple Routers Remote Code Execution Vulnerability
CVE-2018-14558
- Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
CVE-2019-14931
- Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
CVE-2020-10987
- Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
CVE-2021-46422
- Telesquare SDT-CW3B1 Command Injection vulnerability
CVE-2022-37055
- D-Link Routers Buffer Overflow Vulnerability
CVE-2024-29269
- Telesquare TLR-2005KSH Command Injection Vulnerability
CVE-2025-10123
- D-Link DIR-823X Command Injection Vulnerability
CVE-2025-55583
- D-Link DIR-868L B1 router Command Injection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
organisation
DNS
It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws.
organisation
TCP
It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws.
organisation
UDP
It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws.
organisation
CVE
The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (
CVE-2021-36260
), Atlassian Confluence (
CVE-2022-26134
), WSO2 (
CVE-2022-29464
), Zyxel (
CVE-2022-30525
), TP-Link (
CVE-2023-1389
), PHP (
CVE-2024-4577
), D-Link (
CVE-2024-10914
), Kubernetes (
CVE-2025-1974
).
organisation
CVE-2022
The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (
CVE-2021-36260
), Atlassian Confluence (
CVE-2022-26134
), WSO2 (
CVE-2022-29464
), Zyxel (
CVE-2022-30525
), TP-Link (
CVE-2023-1389
), PHP (
CVE-2024-4577
), D-Link (
CVE-2024-10914
), Kubernetes (
CVE-2025-1974
).
organisation
Zyxel
The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (
CVE-2021-36260
), Atlassian Confluence (
CVE-2022-26134
), WSO2 (
CVE-2022-29464
), Zyxel (
CVE-2022-30525
), TP-Link (
CVE-2023-1389
), PHP (
CVE-2024-4577
), D-Link (
CVE-2024-10914
), Kubernetes (
CVE-2025-1974
).
organisation
PHP
The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (
CVE-2021-36260
), Atlassian Confluence (
CVE-2022-26134
), WSO2 (
CVE-2022-29464
), Zyxel (
CVE-2022-30525
), TP-Link (
CVE-2023-1389
), PHP (
CVE-2024-4577
), D-Link (
CVE-2024-10914
), Kubernetes (
CVE-2025-1974
).
organisation
IP
The proxy component, on the other hand, transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection.
August 13
Threat actors used a known flaw in the Linux operating system to exploit vulnerabilities and turn Edge devices into SOCKS5 proxies.
Click on any entity below to view its context and source!
tactic
Botnet
A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin, shared
an analysis
of the new botnet family on August 13, which she called ‘Evooo1Bot’ after the hardcoded string ‘evooo1’ found in every binary.
target_region
Taiwan, Province of China
A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin, shared
an analysis
of the new botnet family on August 13, which she called ‘Evooo1Bot’ after the hardcoded string ‘evooo1’ found in every binary.
organisation
Fortinet’s FortiGuard Labs
A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin, shared
an analysis
of the new botnet family on August 13, which she called ‘Evooo1Bot’ after the hardcoded string ‘evooo1’ found in every binary.
2026/08/14
Threat actors used the Evooo1Bot Linux Botnet to exploit known flaws in Edge devices and turn them into SOCKS5 proxies.
Click on any entity below to view its context and source!
tactic
Ddos
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless
modern malware variants
that continue to reuse Mirai's DDoS engine today.
attribution
Hack Forums
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless
modern malware variants
that continue to reuse Mirai's DDoS engine today.
attribution
FBI
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless
modern malware variants
that continue to reuse Mirai's DDoS engine today.
Aug 17, 2026
Threat actors used a DDoS engine from the publicly leaked Mirai source code to exploit known vulnerabilities in Edge devices and turn them into SOCKS5 proxies.
Click on any entity below to view its context and source!
organisation
DDoS
"While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs
said
.
organisation
SSH
"While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs
said
.
2026/08/17
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies.
Click on any entity below to view its context and source!
infrastructure
Linux
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies.
Ravie Lakshmanan
Aug 17, 2026
Malware / Botnet
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed
Evooo1Bot
that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS.
Yet another
Mirai-derived
botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious capabilities.
"Evooo1Bot is a
Linux botnet
family that incorporates the Mirai DDoS engine into a significantly more capable and modular framework," Fortiguard Labs threat researcher Cara Lin explained in the report.
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies.
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
Evooo1Bot reuses the DDoS engine from the publicly
leaked Mirai
source code, but goes much further than that, giving attackers a multifunctional platform for compromising and monetizing vulnerable Linux-based devices, she said.
organisation
Mirai
Ravie Lakshmanan
Aug 17, 2026
Malware / Botnet
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed
Evooo1Bot
that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Yet another
Mirai-derived
botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious capabilities.
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
organisation
Alcatel
The
botnet,
tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to
a report
published Friday.
organisation
NETGEAR
The
botnet,
tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to
a report
published Friday.
organisation
Tenda
The
botnet,
tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to
a report
published Friday.
Tenda AC1900 Router AC15 Model RCE vulnerability
CVE-2021-46422:
organisation
Mitsubishi Electric
The
botnet,
tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to
a report
published Friday.
organisation
Telesquare
The
botnet,
tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to
a report
published Friday.
Telesquare SDT-CW3B1 command injection vulnerability
CVE-2022-37055: D-Link Routers buffer overflow vulnerability
CVE-2024-29269, Telesquare TLR-2005KSH command injection vulnerability
CVE-2025-10123, D-Link DIR-823X command injection vulnerability
CVE-2025-55583: D-Link DIR-868L B1 router command injection vulnerability
All payload callbacks for these exploitation attempts pointed to the same loader URL at 91.92.40[.]118/wget.sh, linked to Evooo1Bot.
organisation
CVE-2018
The botnet's entry points are an
expansive range of flaws
that remain unpatched on the devices, including command injection and remote code execution bugs such as
CVE-2007-3010
,
CVE-2016-6277
,
CVE-2018-14558
,
CVE-2019-14931
, and
CVE-2020-10987
, among others.
organisation
OG' Social Engineer
"That last part is what Fortinet flags as most significant, and rightly so."
Related:
Sherlock Holmes Was the 'OG' Social Engineer
This functionality means that the botnet can turn a compromised edge device into full attacker infrastructure that "hides their real location, gives them a foothold to pivot deeper into your network, and can be rented out as a residential proxy to other criminals," Ahmed explains.
organisation
Fortigauard
This means that, overall, organizations should treat vulnerable edge devices as potential footholds into internal networks, rather than viewing them solely as
DDoS-botnet risks
, according to Fortigauard.
organisation
CVE-2018-14558
The botnet was discovered after observed exploitation of the following vulnerabilities:
CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability
CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability
CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection vulnerability
CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote command injection vulnerability
CVE-2020-10987:
organisation
Mitsubishi Electric Europe B.V. ME-RTU
The botnet was discovered after observed exploitation of the following vulnerabilities:
CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability
CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability
CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection vulnerability
CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote command injection vulnerability
CVE-2020-10987:
organisation
INEA ME-RTU
The botnet was discovered after observed exploitation of the following vulnerabilities:
CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability
CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability
CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection vulnerability
CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote command injection vulnerability
CVE-2020-10987:
infrastructure
14558 Alcatel OmniPCX remote code execution
The botnet was discovered after observed exploitation of the following vulnerabilities:
CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability
CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability
CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection vulnerability
CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote command injection vulnerability
CVE-2020-10987:
organisation
DDoS
Mirai is a notorious malware strain that infects internet-of-things (IoT) devices using default credentials, turning them into a massive networks – a botnet – to launch DDoS attacks.
Evooo1Bot reuses the DDoS engine from the publicly
leaked Mirai
source code, but goes much further than that, giving attackers a multifunctional platform for compromising and monetizing vulnerable Linux-based devices, she said.
organisation
IoT
Mirai is a notorious malware strain that infects internet-of-things (IoT) devices using default credentials, turning them into a massive networks – a botnet – to launch DDoS attacks.
organisation
Smart Devices
Read now: New Mirai Botnet Exploits Zero-Days in Routers and Smart Devices
organisation
Evooo1Bot
While previous
Mirai-based botnets
also incorporated activity beyond DDoS into their arsenals, Evooo1Bot's reverse SOCKS relay module is a key advancement and "arguably the most operationally significant," according to Lin.
organisation
Defending Against Mirai Variants
Defending Against Mirai Variants
Evooo1Bot once again demonstrates how Mirai's leaked codebase continues to be the gift that keeps on giving for attackers, and how
spinoff Mirai botnets
continue to evolve from relatively straightforward DDoS threats into multipurpose access platforms.
organisation
SSH
Related:
What Boards Need to Know About Tech Risk
"It extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Lin wrote.
Despite working
from the Mirai framework
, the developers of Evooo1Bot have significantly extended their malware with numerous capabilities, including:
Encrypted command-and-control (C2) communications and a 28-command remote administration interface
An SSH brute-force scanner
A reverse SOCKS relay module
Multiple layers of string obfuscation using AES-256-CTR, ChaCha20 and XOR-based key derivation
A credential sniffer
An integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment and enterprise applications
Lin highlighted that the SOCKS relay module is “arguably the most operationally significant” as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.
organisation
AES-256-CTR
Despite working
from the Mirai framework
, the developers of Evooo1Bot have significantly extended their malware with numerous capabilities, including:
Encrypted command-and-control (C2) communications and a 28-command remote administration interface
An SSH brute-force scanner
A reverse SOCKS relay module
Multiple layers of string obfuscation using AES-256-CTR, ChaCha20 and XOR-based key derivation
A credential sniffer
An integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment and enterprise applications
Lin highlighted that the SOCKS relay module is “arguably the most operationally significant” as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.
organisation
XOR
Despite working
from the Mirai framework
, the developers of Evooo1Bot have significantly extended their malware with numerous capabilities, including:
Encrypted command-and-control (C2) communications and a 28-command remote administration interface
An SSH brute-force scanner
A reverse SOCKS relay module
Multiple layers of string obfuscation using AES-256-CTR, ChaCha20 and XOR-based key derivation
A credential sniffer
An integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment and enterprise applications
Lin highlighted that the SOCKS relay module is “arguably the most operationally significant” as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.
organisation
CVE-2022-37055
Telesquare SDT-CW3B1 command injection vulnerability
CVE-2022-37055: D-Link Routers buffer overflow vulnerability
CVE-2024-29269, Telesquare TLR-2005KSH command injection vulnerability
CVE-2025-10123, D-Link DIR-823X command injection vulnerability
CVE-2025-55583: D-Link DIR-868L B1 router command injection vulnerability
All payload callbacks for these exploitation attempts pointed to the same loader URL at 91.92.40[.]118/wget.sh, linked to Evooo1Bot.
organisation
CVE-2025-10123
Telesquare SDT-CW3B1 command injection vulnerability
CVE-2022-37055: D-Link Routers buffer overflow vulnerability
CVE-2024-29269, Telesquare TLR-2005KSH command injection vulnerability
CVE-2025-10123, D-Link DIR-823X command injection vulnerability
CVE-2025-55583: D-Link DIR-868L B1 router command injection vulnerability
All payload callbacks for these exploitation attempts pointed to the same loader URL at 91.92.40[.]118/wget.sh, linked to Evooo1Bot.
organisation
IPS
Evooo1Bot's Add-On Activity
FortiGuard discovered Evooo1Bot through its IPS telemetry when the researchers observed exploitation activity targeting a range of edge devices, with all payload callbacks pointing to the same loader URL at 91.92.40[.]118/wget.sh, according to the report.
organisation
TCP
Once installed, Evooo1Bot can establish encrypted command-and-control (C2) communications over TCP port 442 and execute commands and maintain persistence through multiple mechanisms, including the systemd service, cron jobs, shell profiles, and other methods.
organisation
IP
"By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure," she wrote.
organisation
GhostJacking
Related:
'GhostJacking' Exposes Identity Governance Gaps in AI Agents
'SOCK' It to Them
organisation
Secure.com
Indeed, while most
post-Mirai bonets
"just add more firepower to knock a target offline," Evooo1Bot doesn't stop at flooding, observes Waseem Ahmed, head of engineering at Secure.com.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies.
Ravie Lakshmanan
Aug 17, 2026
Malware / Botnet
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed
Evooo1Bot
that derives its core functionality from the Mirai botnet source code and is equipped to…
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS.
Yet another
Mirai-derived
botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious capabilities.
"Evooo1Bot is a
Linux botnet
family that incorporates the Mirai DDoS engine into a significantly more capable and modular framework," Fortiguard Labs threat researcher Cara Lin explained in the report.
Evooo1Bot reuses the DDoS engine from the publicly
leaked Mirai
source code, but goes much further than that, giving attackers a multifunctional platform for compromising and monetizing vulnerable Linux-based devices, she said.
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies.
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
Metrics
infrastructure
91.92.40
Software Version
…ection Vulnerability
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture.
Metrics
infrastructure
14,558
Alcatel Omnipcx Remote Code Execution
The botnet was discovered after observed exploitation of the following vulnerabilities:
CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution (RCE) vulnerability
CVE-2016-6277: NETGEAR Multiple Routers RCE vulnerability
CV…
Intelligence Sources
Infosecurity-Magazine
2026-08-14
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Infosecurity-Magazine
The Hacker News
2026-08-17
Dark Reading
2026-08-17
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-18T06:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
37x
organisation
Identified Entity
Mirai
entity
18x
vulnerability
Exploited CVE
CVE-2007-3010
cve
9x
timeline
Temporal Reference
2026
date
4x
tactic
Cyber Operation Type
Botnet
tactic
4x
tactic
MITRE ATT&CK Technique
T1584.005 - Botnet
technique
2x
attribution
Attributing Entity
Hack Forums
authority
Contextual Telemetry
Context Block
12 METRICS
infrastructure
Affected Product
Linux
software
general metric
Aug
17
aug
target region
Target Region
EUROPE
region
infrastructure
Software Version
91.92.40
version
general metric
Netgear
6,277
netgear
general metric
Cve-2018 Tenda Ac7
14,558
cve-2018 tenda ac7
general metric
Port
443
port
industry
Targeted Sector
Defense
sector
general metric
Tcp Port
442
tcp port
target region
Target Country
Taiwan, Province of China
country
infrastructure
Alcatel Omnipcx Remote Code Execution
14,558
alcatel omnipcx remote code execution
general metric
Command
28
command
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.