Evooo1Bot Linux Botnet
According to cybersecurity researchers, there is a newly discovered botnet in Linux that has been quietly building an army of compromised devices since July 2026. Dubbed Evooo1Bot, the malware uses the source code of the infamous Mirai botnet but with many more additional capabilities. Its main goal? Turning routers, cameras, and other internet-connected gadgets into proxy servers for cybercriminals.
The Evooo1Bot Linux botnet doesn't just recycle old code. The attackers took Mirai's DDoS engine and built a whole new set of capabilities around it. We're talking encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an exploit arsenal that targets nearly 20 known vulnerabilities.
Fortinet FortiGuard Labs discovered and analyzed the Evooo1Bot Linux botnet. Let me walk you through what it does, how it spreads, and what it means for your organization.
Key Facts Related to Evooo1Bot
- Evooo1Bot is a Mirai variant Linux botnet which has been active since July 2026
- Infected devices such as routers and webcams act as SOCKS5 proxies
- Supports encryption in communication and has SSH scanner capabilities
- Takes advantage of 18 different vulnerabilities on routers, firewalls, and other IoT devices
- Utilizes port 443 which disguises itself in legitimate HTTPS traffic
What Exactly Is Evooo1Bot?
The Evooo1Bot Linux botnet is built on the bones of Mirai, the malware that made headlines in 2016 when it took down huge chunks of the internet. But Evooo1Bot is much more than just a copy-paste job.
These attackers have included some additional modules that transform the infected devices into versatile cyber-crime tools. This piece of malware does not simply wait for the command to execute DDoS attacks. It can also act as a proxy, steal credentials, brute-force SSH passwords, and exploit new vulnerabilities.
How Does It Spread on Devices?
The Evooo1Bot Linux botnet spreads by exploiting existing vulnerabilities in internet-connected devices. Once it detects a vulnerable system, the botnet runs a loader script from an external server. The script downloads the botnet code for that particular device’s CPU architecture.
For hiding itself from the user, the script cleans up the Bash history file. The device owner might never know their system has been compromised. The infection is silent and invisible.
The Exploit Arsenal
The Evooo1Bot Linux botnet comes with an impressive collection of exploits. It exploits 18 vulnerabilities on many different kinds of devices:
Router and IoT Flaws:
- CVE-2007-3010 – Alcatel OmniPCX Enterprise
- CVE-2016-6277 – NETGEAR Multiple Routers
- CVE-2018-14558 – Tenda AC7, AC9, AC10
- CVE-2020-10987 – Tenda AC1900 Router AC15
- CVE-2021-46422 – Telesquare SDT-CW3B1
- CVE-2022-37055 – D-Link Routers
- CVE-2024-29269 – Telesquare TLR-2005KSH
- CVE-2025-10123 – D-Link DIR-823X
- CVE-2025-55583 – D-Link DIR-868L B1
Additional Targets:
- CVE-2021-36260 – Hikvision cameras
- CVE-2022-26134 – Atlassian Confluence
- CVE-2022-29464 – WSO2
- CVE-2022-30525 – Zyxel
- CVE-2023-1389 – TP-Link
- CVE-2024-4577 – PHP
- CVE-2024-10914 – D-Link
- CVE-2025-1974 – Kubernetes
That's a lot of ways to get in. The Evooo1Bot Linux botnet casts a wide net, targeting everything from home routers to enterprise-grade systems.
The SOCKS5 Proxy: Getting the Best Out of It
The ability to turn the infected computers into SOCKS5 proxies is certainly the most dangerous element of the Evooo1Bot Linux botnet.
How It Works:
If the device gets infected by the malware, it can turn it into a SOCKS5 proxy server where the attacker will route their traffic through the compromised device.
Why This Is Useful:
- The traffic of the attacker is masqueraded as originating from the IP address of the victim.
- They can bypass geographical limitations and filters
- They can access the internal network through the compromised machine
The Business Model:
In larger botnets, the Evooo1Bot Linux botnet could be used to build a distributed proxy infrastructure. These proxies could be sold by cybercriminals. It is possible that corporations are buying residential proxy services from providers who are using compromised devices.
This turns a simple DDoS botnet into a revenue-generating operation. This is a huge improvement over the existing Mirai.
Encryption of C2 Communication Channels
The Evooo1Bot Linux botnet employs encrypted communication channels with the C2 server, making detection by securitytools more difficult.
C2 Connection:
The bot establishes the connection on port 443, which is usually used for HTTPS traffic. Thus, the malware disguises itself among legitimate network traffic.
Registration process:
At the time when the device is infected, the malware examines for any analysis, sandboxes or virtualization systems. In case there are none, it establishes an encrypted connection to the C2 server. It registers and waits for instructions.
Capabilities of the Botnet:
Some of the capabilities of the Evoo1Bot Linux botnet include the following:
- Install persistence for the bot
- Upgrade to the most recent version of the binary
- Kill the bot in case it is necessary
- Transfer files back and forth
- Spawn an interactive shell
- Steal HTTP Basic Auth and Cookies
- Make the compromised machine act as a proxy server
- Execute an SSH brute-forcer
- Cause DDoS attacks through DNS, TCP, and UDP
- Deploy an HTTP exploit dispatcher
This makes Evooo1Bot a versatile tool for cybercriminals. It may be used for stealing information, credential theft, and massive DDoS attacks.
The SSH Brute-Force Scanner
Evoo1Bot Linux Botnet has a built-in SSH brute-force scanner used to crack into other systems.
How It Works:
The malware attempts to use standard user names and passwords. The malware will also attempt to use credentials that were exposed in past compromises.
The Credential Sniffer:
The malware is also capable of capturing HTTP Basic Authorization and Cookie headers. This allows it to grab the user’s credentials when they travel across the network.
The Worth of the Credentials:
Compromised credentials may be used in additional attacks. The credentials may also be sold to other cybercriminals on the dark web. This makes Evooo1Bot a lucrative operation.
What This Means for Organizations
The Evooo1Bot Linux botnet is a reminder that IoT devices are a major weak spot in network security.
The Problem:
Many organizations have routers, firewalls, and IP cameras on their networks. These devices generally come preloaded with outdated firmware. Also, they often make use of default passwords.
Risk:
- The device is compromised and can be utilized as a proxy node.
- The attacker can conceal his movements with the help of proxy nodes.
- Internal network may be accessed through compromising edge devices.
What Organizations Must Do
In case of Evooo1Bot Linux botnet, the following should be done:
- Find All Compromised Devices:
- Monitor all compromised devices.
- Never neglect routers, cameras, and other Internet-of-Things (IoT) devices.
Security Patches and Updates:
- Install security patches immediately
- Look out for firmware update notices
Password Change – Default Passwords:
- Use secure and unique passwords
- Avoid using the same password across devices
Monitoring of Network Traffic:
- Look out for any abnormal outbound traffic from port 443
- Look out for any proxy abuse
- Look out for any abnormal SSH connections
Limitations to Access:
- Segment the network for IoT devices
- Restrict access to admin portal
Conclusion
The Evooo1Bot Linux botnet is a highly dangerous threat to the security of IoT devices. Routers, cameras, and firewalls become SOCKS5 proxies for cybercriminals.
Main facts about Evooo1Bot:
- It is an upgraded version of Mirai but with numerous modifications
- Active since July 2026
- Exploits 18 known vulnerabilities
- Makes devices act as SOCKS5 proxies
- Uses encrypted C2 communications
- Equipped with an SSH brute-force scanner
- Steals credentials from HTTP traffic
IoT devices must be inventoried to find the exposed ones. The system must be patched immediately. Default passwords must be changed.
Evooo1Bot Linux botnet serves as a reminder that every device connected to the internet is an entry point.
FAQ Section
What is the Evooo1Bot Linux botnet?
Evooo1Bot is a Mirai-based botnet that turns internet-facing devices into SOCKS5 proxies. These include C2 communication channels which are encrypted, SSH brute-forcer scanner, and a set of exploits, which target 18 vulnerabilities.
What is the method of propagation of Evooo1Bot?
Evooo1Bot exploits vulnerabilities in various Internet of Things (IoT) devices including routers and firewalls. After infection, it downloads a loader script which gets the botnet binary and clears the Bash history.
What devices are targeted?
The botnet targets a variety of devices such as Tenda, D-Link, NETGEAR, Alcatel, Telesquare, Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, and Kubernetes.
What is SOCKS5 proxy functionality?
The malware has the capability to make an infected device into a SOCKS5 proxy server. The attacker can use such proxies to mask his traffic and bypass geo-blocking.
What should organizations do?
Detect exposed IoT devices, deploy patches, update default passwords, analyze network traffic for anomalies, and limit access to the administration interfaces.