#Evooo1Bot
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
www.bleepingcomputer.com
August 15, 2026 at 2:15 PM
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.

Source: BleepingComputer
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
www.bleepingcomputer.com
August 15, 2026 at 8:34 PM
Evooo1Bot Linux Botnet Converts Routers Into Traffic Relay Nodes Evooo1Bot: Turning Edge Devices into Multi-Purpose Traffic Relays Evooo1Bot is a modular Linux botnet that.... @cosmicmeta.ai

https://u2m.io/UODFNoHw
Evooo1Bot Linux Botnet Converts Routers Into Traffic Relay Nodes
Evooo1Bot: Turning Edge Devices into Multi-Purpose Traffic Relays Evooo1Bot is a modular Linux botnet that hijacks exposed routers and gateway
thecosmicmeta.com
August 15, 2026 at 4:09 PM
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that reaches internet-facing edge systems by exploiting known flaws and attempting weak SSH logins. Its operators can then issue commands through an encrypted control channel. The campaign is more than another basic denial-of-service operation. It combines code drawn from the leaked Mirai framework with proxy, credential-sniffing, file-transfer, and exploit functions. That mix gives intruders several ways to use a single compromised device and mirrors  recent Mirai botnet trends  toward broader abuse. Fortinet  analysts identified the malware after seeing active exploitation attempts against a range of edge devices. Fortinet said in a report shared with Cyber Security News (CSN) that telemetry showed the botnet targeting internet-facing devices from July 2026, with campaigns tracked separately by the weakness used. The immediate danger is not limited to a device going offline. An infected system can be enlisted in attacks against others, used to hide an operator’s connection, or serve as a stepping stone toward internal resources. Payload in exploit pcap (Source – Fortinet) The threat therefore adds weight to  edge device defense lessons  for organizations that leave appliances exposed and unpatched. Sixteen DDoS Methods Expand the Threat Evooo1Bot carries 16 traffic-flooding methods, including UDP, DNS, SYN, GRE, and fragmented TCP attacks. The engine is structurally consistent with leaked Mirai code, but its HTTP flood function can accept operator-selected request methods, headers, and expected values. That flexibility can make malicious traffic look less uniform during an attack. The bot also contains an exploit dispatcher that can deliver payloads through known weaknesses in products from vendors including D-Link, Tenda, Hikvision, Zyxel, TP-Link, and others. Some entries do not work as implemented, but the list still helps operators test many targets. It also reinforces why  network device patching practices  remain central to limiting botnet growth. Following compromise, a loader retrieves the binary suited to the victim’s processor, runs it temporarily, then clears Bash history. The malware can establish persistence through system services, startup scripts, scheduled tasks, shell profiles, and rc.local. wget.sh (Source – Fortinet) It also checks for analysis tools, sandboxes, virtual machines, and containers before connecting to its command server on port 443. For defenders, the concern is scale. Each infected appliance can add attack capacity and fresh access points. Prompt firmware updates, removal of unnecessary public exposure, strong unique administrative credentials, and monitoring of unusual outbound connections are the basic steps that reduce that opportunity. SOCKS5 Proxies Turn Victims Into Relays The SOCKS relay module makes Evooo1Bot especially useful beyond denial-of-service attacks. In direct mode, it can open a SOCKS5 listener, normally on TCP port 1080. In reverse mode, the bot creates encrypted outbound links to an operator-selected relay server, allowing traffic to pass through the victim without exposing a listener to the internet. That design can conceal the real source of malicious activity, help bypass location-based controls, and provide a route into networks behind a compromised device. Similar  SOCKS5 proxy abuse tactics  show why defenders should treat unexplained proxy behavior as an intrusion signal rather than a minor network anomaly. Evooo1Bot also includes an SSH scanner with more than 150 embedded credentials, including service-account names used in business environments. XOR-encoded string (Source – Fortinet) It tries to avoid honeypots by checking SSH banners and probing a successful target for signs of emulation. A separate sniffer can collect HTTP Basic Authorization and Cookie headers, raising the potential cost of an infection. Organizations should inventory internet-exposed equipment, apply vendor fixes quickly, disable remote management where it is not needed, and review outbound encrypted sessions from appliances that rarely initiate them. Network teams should also investigate new SOCKS listeners, unexpected scheduled downloads, and systems contacting the listed infrastructure. They cannot remove an existing compromise alone, but they help teams find and contain it early. Indicators of Compromise (IoCs):- Type Indicator Description IP address 91.92.40[.]118 Command-and-control infrastructure and loader host observed in the campaign URL http://91.92.40[.]118/wget.sh Loader URL used in payload callbacks File name wget.sh Loader script that downloads and executes architecture-matched binaries SHA-256 f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109 Evooo1Bot sample hash SHA-256 4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d Evooo1Bot sample hash Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Stop new phishing & malware before they compromise your business.  Integrate live intel from 15K SOCs around the world The post Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices appeared first on Cyber Security News .
cybersecuritynews.com
August 17, 2026 at 7:28 AM
120 secondes de Tech / 17 aout 2026
– La France bloque l’interdiction aux moins de 15 ans
– Evooo1Bot infecte des appareils connectés
– Apple ouvre la réservation de publicités dans Plans
– ChatGPT lance Computer History sur Mac
– Google permet de retirer le filigrane visible de Gemini
August 17, 2026 at 9:32 AM
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services.
securityaffairs.com
August 18, 2026 at 7:39 AM
August 15, 2026 at 9:17 PM
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

huntaegis.com
August 18, 2026 at 8:01 AM
A new Mirai-variant botnet is weaponizing routers as traffic relays. Evooo1Bot targets gateway devices to mask attacker traffic—critical…

https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/

#cybersecurity #infosec
August 22, 2026 at 11:30 AM
Usurpation d’équipements réseau : le botnet Linux Evooo1Bot transforme les routeurs en proxies d’attaque

Vos équipements réseau Linux sous la menace ! Le botnet Evooo1Bot détourne routeurs et caméras pour créer des...

https://goodtech.info/evooo1bot-botnet-linux-relais-proxy-socks5-fortinet/
Usurpation d’équipements réseau : le botnet Linux Evooo1Bot transforme les routeurs en proxies d’attaque
Vos équipements réseau Linux sous la menace ! Le botnet Evooo1Bot détourne routeurs et caméras pour créer des relais proxy SOCKS5 invisibles. Découvrez l'analyse des chercheurs de Fortinet. Certes, la réutilisation du code source de Mirai pour mener des attaques par déni de service distribué est une pratique éprouvée, mais la sophistication des logiciels malveillants...
goodtech.info
August 19, 2026 at 6:19 AM
A newly identified Linux botnet called Evooo1Bot is conscripting routers and using them as traffic relay nodes. It appears in reporting alongside Mirai, Dysphoria and AryStinger, a reminder that edge network gear is a live target.
Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes
A newly identified Linux botnet called Evooo1Bot is conscripting routers and using them as traffic relay nodes. It appears in reporting alongside Mirai, Dysphoria and AryStinger, a reminder that edge network gear is a live target.
captechgroup.com
August 15, 2026 at 6:14 PM
FortiGuard Labs uncovered Evooo1Bot, a new Linux botnet using Mirai DDoS code plus encrypted C2, credential theft, SOCKS relay, SSH brute forcing, and multi-exploit targeting Internet-facing devices. #Evooo1Bot #Mirai #Linux
Multi-Functional Linux Botnet “Evooo1Bot”
FortiGuard Labs identified Evooo1Bot, a previously undocumented Linux botnet that repurposes Mirai’s DDoS engine while adding encrypted C2, credential theft, SOCKS relay, SSH brute forcing, and a multi-vulnerability exploit framework. Active since July 2026, it targets Internet-facing devices through a loader hosted at 91.92.40[.]118 and uses campaigns against products from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, D-Link, Telesquare, Hikvision, and others. #Evooo1Bot #Mirai #FortiGuardLabs #Alcatel #NETGEAR #Tenda #MitsubishiElectric #DLink #Telesquare #Hikvision
www.hendryadrian.com
September 16, 2026 at 10:15 AM
Evooo1Bot is a serious threat to Edge devices. Pro tip: Audit your Linux systems, disable unused ports, and update credentials. Great catch on the SOCKS5 proxy usage!
August 17, 2026 at 7:58 AM
Nuova botnet Linux Evooo1Bot: trasforma router e firewall in proxy segreti per gli hacker

📌 Link all'articolo : www.redhotcyber.com/post/nuova-b...

Carolina Vivianti

#redhotcyber #cybersecurity #cybercrime #hacking #cti #ai #privacy #news #technology
August 20, 2026 at 6:20 AM
-78k TeamPCP stolen creds leak online
-737 malicious Chrome extensions spotted
-Vuln-scan campaign poses as AI crawlers
-Deadbugz campaign tries to poison AI tools
-More AI tools found on hacking forums
-Deno runtime sees increased abuse
-Crypter ecosystem has 24 sellers
-New Evooo1Bot botnet
August 14, 2026 at 8:46 AM
Ein neues Linux-Botnetz kapert Router, Firewalls und Kameras — verschlüsselt aber nichts und erpresst niemanden.

Es leitet fremden Verkehr über Ihre IP-Adresse. Der Schaden zeigt sich als abgelehnte E-Mails, nicht als Angriff.

Die älteste ausgenutzte Lücke ist 19 Jahre alt.
Botnetz kapert Router und nutzt sie als Proxy
Evooo1Bot verschlüsselt nichts und erpresst niemanden — es leitet fremden Verkehr über Ihre IP. Woran Sie es merken und welche Geräte betroffen sind.
cyberdine.ch
August 29, 2026 at 10:43 PM
A new Linux botnet called Evooo1Bot is targeting enterprise firewalls, SOHO routers, IP cameras, and industrial RTUs and it's doing more than launching DDoS attacks.

Read the full breakdown: fastnetmon.com/2026/08/19/ddos-news-evooo1bot-linux-botnet-hijacks-routers-and-firewalls/

#DDoS #Botnet
September 3, 2026 at 11:00 AM