Evooo1Bot is a modular, Mirai-derived Linux botnet observed targeting internet-facing devices across multiple regions since July 2026. It compromises routers, firewalls, IP cameras, and other edge systems through known vulnerabilities and weak SSH credentials. Observed exploitation targets include products from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. An architecture-aware shell loader retrieves and executes an appropriate Linux binary and clears Bash history to conceal the intrusion.
The malware combines Mirai’s DDoS engine with encrypted command-and-control, SSH brute-force scanning, credential interception, remote shell access, file transfer, self-updating, and vulnerability exploitation. Its DDoS functionality includes UDP, DNS, TCP, and GRE flooding, alongside configurable HTTP floods. A credential-sniffing module captures HTTP Basic Authentication data and cookies. The SSH scanner uses more than 150 credential entries and checks targets for honeypot indicators before and after authentication. Newer builds expose a 28-command remote administration interface and an embedded exploit dispatcher, although some exploit entries are incorrectly implemented and cannot compromise their claimed targets as shipped.
Evooo1Bot converts infected systems into SOCKS5 proxies through direct-listening or encrypted reverse-relay modes. These capabilities let operators conceal traffic origins and reach internal resources accessible through compromised devices. Persistence uses systemd services, SysV initialization, scheduled tasks, and shell startup modifications. Layered AES-256-CTR, ChaCha20, and XOR string obfuscation, checks for analysis tools and virtualized environments, and encrypted control connections over TCP port 443 support defense evasion. No specific threat-actor attribution has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-1389 TP-Link Archer AX21 /cgi-bin/luci/;stok=/locale | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2025-55583: D-Link DIR-868L B1 router Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2021-36260 Hikvision IP Camera /SDK/webLanguage | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2025-10123, D-Link DIR-823X Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2025-1974 Kubernetes ingress-nginx /apis/networking/v1/ingresses | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2024-29269, Telesquare TLR-2005KSH Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2024-4577 PHP-CGI (Windows) allow_url_include%3D | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2022-30525 Zyxel Firewall /ztp/cgi-bin/handler | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2007-3010: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2022-26134 Atlassian Confluence /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2024-10914 D-Link NAS /cgi-bin/account_mgr.cgi | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2022-29464 WSO2 products /fileupload/ | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
CVE-2021-46422: Telesquare SDT-CW3B1 Command Injection vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Дополнительно создается cron-задача, которая каждые пять минут пытается повторно скачать пейлоад.
Les chaînes statiques sont protégées par un pipeline multi-couches : Chiffrement AES-256-CTR et ChaCha20 ... Encodage XOR supplémentaire
После этого скрипт очищает историю Bash, чтобы скрыть следы атаки.
Еще один компонент отвечает за брутфорс SSH и перебирает 150 комбинаций имен пользователей и паролей
SSH brute-force scanner module Used to compromise additional devices via weak SSH credentials
Если все «чисто», Evooo1Bot устанавливает зашифрованное соединение с управляющим сервером через порт 443, маскируя свой трафик под обычный HTTPS.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Малварь атакует доступные через интернет роутеры, файрволы, IP-камеры и другие пограничные устройства, превращая их в SOCKS5-прокси.
The proxy component transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux botnet derived from Mirai source code that compromises internet-exposed edge devices, turns them into SOCKS5 proxies, steals credentials, brute-forces SSH, provides interactive shell access, maintains persistence, and supports DDoS attacks.
A Mirai-based Linux botnet that compromises routers and IoT devices. It reuses Mirai's DDoS engine and adds encrypted C2, SSH brute-force scanning, credential sniffing, SOCKS5 proxying, exploit modules, persistence, shell access, file transfer, and multi-protocol DDoS capabilities.
Linux botnet family with Mirai-derived DDoS capabilities that adds multi-layer string obfuscation, anti-analysis checks, persistence, file transfer, interactive shell access, network sniffing, SOCKS5 proxying, SSH brute-force/scanning, embedded CVE exploitation, and multiple DDoS methods.
A Mirai-derived Linux botnet that combines DDoS capability with encrypted C2, SSH brute-force scanning, credential sniffing, reverse SOCKS relay/proxying, persistence mechanisms, anti-analysis checks, and an exploit arsenal targeting Internet-facing edge devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.