Evooo1Bot is a Mirai-derived modular Linux botnet that targets internet-facing routers, gateway devices, firewalls, IP cameras, and other edge systems. It reuses Mirai’s distributed denial-of-service engine while extending the framework with encrypted command-and-control communications, a SOCKS5 relay capability, SSH brute-force scanning, credential-sniffing functions, file transfer, interactive shell access, persistence mechanisms, and an integrated exploit module for multiple known vulnerabilities.
The malware has been observed exploiting known flaws in exposed devices from vendors including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, with newer builds also containing exploit logic aimed at additional enterprise and edge technologies such as Hikvision, Atlassian Confluence, Zyxel, TP-Link, D-Link NAS, WSO2, Kubernetes ingress-nginx, and PHP-CGI targets. Successful compromise leads to delivery of an architecture-matched Linux payload, after which the malware removes traces of execution, performs anti-analysis and anti-sandbox checks, and establishes encrypted communications with its operators.
A defining feature of Evooo1Bot is its ability to convert compromised devices into SOCKS5 proxy nodes, including reverse-relay operation, allowing operators to route malicious traffic through victim infrastructure for concealment, follow-on intrusion activity, and potential proxy monetization. It also supports SSH brute forcing with honeypot-aware checks, captures HTTP Basic Authorization and Cookie headers, and can execute remote shell and file-management commands. Persistence has been observed through multiple Linux startup mechanisms and recurring task scheduling, enabling long-term botnet enrollment.
In addition to proxying and credential collection, Evooo1Bot retains substantial DDoS functionality inherited from Mirai, including multiple UDP-, TCP-, DNS-, GRE-, and HTTP-based flood methods. The malware’s combination of botnet, proxy, credential theft, exploitation, and post-compromise control capabilities makes it more versatile than conventional Mirai variants and particularly relevant to organizations operating exposed Linux-based edge infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Модулот за CVE напади има можност да активира експлоатации за осум безбедносни ранливости кои ги засегаат ... TP-Link (CVE-2023-1389) ... | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Модулот за CVE напади има можност да активира експлоатации за осум безбедносни ранливости кои ги засегаат ... Kubernetes (CVE-2025-1974). | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Some of the security flaws weaponized by the botnet are below - CVE-2025-55583 - D-Link DIR-868L B1 router Command Injection Vulnerability | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Некои од безбедносните пропусти што ги злоупотребува ботнетот се: CVE-2025-10123 – ранливост за Command Injection во D-Link DIR-823X. | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Модулот за CVE напади има можност да активира експлоатации за осум безбедносни ранливости кои ги засегаат Hikvision (CVE-2021-36260)... | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Some of the security flaws weaponized by the botnet are below - CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Некои од безбедносните пропусти што ги злоупотребува ботнетот се: CVE-2020-10987 – ранливост за далечинско извршување код во Tenda AC1900 AC15 рутер. | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
The CVE attack module includes the ability to launch exploits for eight security flaws impacting Zyxel (CVE-2022-30525) | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
The CVE attack module includes the ability to launch exploits for eight security flaws impacting WSO2 (CVE-2022-29464) | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Некои од безбедносните пропусти што ги злоупотребува ботнетот се: CVE-2018-14558 – ранливост за Command Injection во Tenda AC7, AC9 и AC10 рутери. | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Модулот за CVE напади има можност да активира експлоатации за осум безбедносни ранливости кои ги засегаат ... D-Link (CVE-2024-10914) ... | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Некои од безбедносните пропусти што ги злоупотребува ботнетот се: CVE-2021-46422 – ранливост за Command Injection во Telesquare SDT-CW3B1. | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
The CVE attack module includes the ability to launch exploits for eight security flaws impacting Atlassian Confluence (CVE-2022-26134) | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Модулот за CVE напади има можност да активира експлоатации за осум безбедносни ранливости кои ги засегаат ... PHP (CVE-2024-4577) ... | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Некои од безбедносните пропусти што ги злоупотребува ботнетот се: CVE-2019-14931 – ранливост за далечински Command Injection во Mitsubishi Electric Europe B.V. ME-RTU и INEA ME-RTU уреди. | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
Some of the security flaws weaponized by the botnet are below - CVE-2022-37055 - D-Link Routers Buffer Overflow Vulnerability | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Some of the security flaws weaponized by the botnet are below - CVE-2007-3010 - Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
Некои од безбедносните пропусти што ги злоупотребува ботнетот се: CVE-2024-29269 – ранливост за Command Injection во Telesquare TLR-2005KSH. | Истражувачите за сајбер-безбедност предупредија на претходно недокументирана Linux ботнет фамилија, наречена Evooo1Bot, која ја презема основната функционалност од изворниот код на Mirai ботнетот и е опремена за претворање на уредите достапни од интернет во SOCKS прокси-сервери.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
A cron job also attempts to download the payload again every five minutes, providing another way to restore the malware if it is removed.
It clears Bash history and establishes persistence through mechanisms including systemd, SysV init, shell profiles and "rc.local".
A cron job also attempts to download the payload again every five minutes, providing another way to restore the malware if it is removed.
It clears Bash history and establishes persistence through mechanisms including systemd, SysV init, shell profiles and "rc.local".
A cron job also attempts to download the payload again every five minutes, providing another way to restore the malware if it is removed.
It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner
Изборот на портата 443 е намерен бидејќи му овозможува на малициозниот софтвер да се меша со очекуваниот HTTPS сообраќај
Upon execution, the binary checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communications with a command-and-control (C2) server on port 443. The port choice is intentional as it allows the malware to blend in with expected HTTPS traffic at the network perimeter.
A new Linux botnet named Evooo1Bot is turning internet-facing routers and other gateway devices into SOCKS5 traffic relay nodes... Evooo1Bot supports both direct-listening and reverse-relay modes, which could help operators conceal the origin of malicious traffic, bypass geographic restrictions or reach networks accessible through compromised devices.
DDoS remains part of the malware's toolkit, with 16 flood methods inherited from Mirai, including UDP, DNS, SYN, ACK, GRE, fragmented TCP and customizable HTTP floods.
It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented Linux botnet that reuses Mirai source code but extends it with encrypted C2 communications, SSH brute-force scanning, SOCKS5 proxy/relay capability, credential sniffing, persistence, file transfer, interactive shell access, DDoS functions, and automated exploitation of known vulnerabilities on internet-exposed edge devices.
A previously undocumented Linux botnet that reuses Mirai's DDoS engine while adding encrypted C2 communications, SSH brute-force scanning, SOCKS proxy/relay capability, credential sniffing, persistence, file transfer, interactive shell access, and exploit modules to compromise internet-facing devices and use them as proxy nodes or for DDoS and follow-on operations.
Mirai-based Linux botnet malware that compromises internet-facing routers and gateway devices, turning them into SOCKS5 relay nodes while also supporting DDoS attacks, SSH brute-forcing, credential sniffing, exploitation of known vulnerabilities, remote shell access, file transfer, persistence, and anti-analysis checks.
Mirai-based modular Linux botnet that compromises internet-facing gateway and IoT devices to operate as SOCKS5 proxy relays, steal credentials, brute-force SSH, maintain persistence, provide interactive shell/file transfer access, and launch DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.