Security News

Cybersecurity news aggregator

CRITICAL Attacks Dark Reading

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

The Evooo1Bot botnet is a modular, Mirai-derived threat targeting Linux-based edge devices by exploiting known command injection and RCE vulnerabilities, such as CVE-2007-3010 (CVSS 9.8), CVE-2016-6277 (CVSS 8.8), and CVE-2018-14558 (CVSS 9.8), to install malware that extends beyond DDoS to include credential theft and SOCKS proxy relays. Affected products include specific firmware versions of Alcatel OmniPCX Enterprise Communication Server (<= 7.1), NETGEAR routers (e.g., D6220 <= 1.0.0.22, R6700 <= 1.0.1.14), and Tenda routers (e.g., AC7 <= 15.03.06.44_cn). The article emphasizes patching these legacy vulnerabilities but does not specify fixed versions or provide explicit workarounds.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK ICS/OT SECURITY VULNERABILITIES & THREATS THREAT INTELLIGENCE NEWS Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure. Elizabeth Montalbano,Contributing Writer August 17, 2026 4 Min Read SORCE: LAURENT DAVOUST VIA ALAMY STOCK PHOTO Yet another Mirai-derived botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious capabilities. The botnet, tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to a report published Friday. LOADING... "Evooo1Bot is a Linux botnet family that incorporates the Mirai DDoS engine into a significantly more capable and modular framework," Fortiguard Labs threat researcher Cara Lin explained in the report. The researchers named the botnet — which exploits a host of vulnerabilities as old as 2007 as well as flaws discovered just last year — after finding the hardcoded string "evooo1" in every binary. Evooo1Bot reuses the DDoS engine from the publicly leaked Mirai source code, but goes much further than that, giving attackers a multifunctional platform for compromising and monetizing vulnerable Linux-based devices, she said. Related:What Boards Need to Know About Tech Risk "It extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Lin wrote. Evooo1Bot's Add-On Activity FortiGuard discovered Evooo1Bot through its IPS telemetry when the researchers observed exploitation activity targeting a range of edge devices, with all payload callbacks pointing to the same loader URL at 91.92.40[.]118/wget.sh, according to the report. LOADING... The botnet's entry points are an expansive range of flaws that remain unpatched on the devices, including command injection and remote code execution bugs such as CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, and CVE-2020-10987, among others. This demonstrates how attackers don't need cutting-edge exploits to threaten organizations, but instead can target forgotten, unpatched devices that carry old vulnerabilities, Lin noted. Once installed, Evooo1Bot can establish encrypted command-and-control (C2) communications over TCP port 442 and execute commands and maintain persistence through multiple mechanisms, including the systemd service, cron jobs, shell profiles, and other methods. It also attempts to detect analysis tools, virtualized environments, and honeypots before proceeding, according to Lin. Combined with the other activity, this latter capability shows extreme maturity, Lin noted. "These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware," she wrote. Related:'GhostJacking' Exposes Identity Governance Gaps in AI Agents 'SOCK' It to Them While previous Mirai-based botnets also incorporated activity beyond DDoS into their arsenals, Evooo1Bot's reverse SOCKS relay module is a key advancement and "arguably the most operationally significant," according to Lin. The functionality gives attackers a way to route subsequent traffic through the victim's own network, providing cover for a host of additional malicious activities. "By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure," she wrote. Indeed, while most post-Mirai bonets "just add more firepower to knock a target offline," Evooo1Bot doesn't stop at flooding, observes Waseem Ahmed, head of engineering at Secure.com. "It brute-forces SSH with a list of enterprise-focused logins ... exploits a long list of known bugs in routers, cameras, and firewalls, and then turns the compromised device into a hidden SOCKS proxy the attacker can route traffic through," Ahmed tells Dark Reading. "That last part is what Fortinet flags as most significant, and rightly so." Related:Sherlock Holmes Was the 'OG' Social Engineer This functionality means that the botnet can turn a compromised edge device into full attacker infrastructure that "hides their real location, gives them a foothold to pivot deeper into your network, and can be rented out as a residential proxy to other criminals," Ahmed explains. "This is also not crude malware as it checks for sandboxes, debuggers, and honeypots before it runs, which tells you botnet development has professionalized." Defending Against Mirai Variants Evooo1Bot once again demonstrates how Mirai's leaked codebase continues to be the gift that keeps on giving for attackers, and how spinoff Mirai botnets continue to evolve from relatively straightforward DDoS threats into multipurpose access platforms. This means that, overall, organizations should treat vulnerable edge devices as potential footholds into internal networks, rather than viewing them solely as DDoS-botnet risks, according to Fortigauard. Immediate priorities for defenders include patching and replacing exposed network appliances, such as devices that may be considered legacy or difficult to upgrade, according to Fortiguard. This is especially important as "some vulnerabilities targeted by Evooo1Bot date back nearly two decades," observes Jacob Krell, senior director of secure AI solutions & cybersecurity for Suzu Labs. Other mitigation and defense steps to take include looking for unauthorized cron jobs, systemd services, init scripts, and shell-profile modifications; investigating unexplained SSH activity and authentication attempts against network infrastructure; and monitoring devices unexpectedly behaving as SOCKS/proxy endpoints. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion More Webinars You May Also Like CYBER RISK How Can CISOs Respond to Ransomware Getting More Violent? by James Doggett JAN 28, 2026 CYBER RISK US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity by Alexander Culafi JAN 05, 2026 CYBER RISK Switching to Offense: US Makes Cyber Strategy Changes by Robert Lemos NOV 21, 2025 CYBER RISK Microsoft Exchange 'Under Imminent Threat,' Act Now by Arielle Waldman NOV 12, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show. Editor's Choice CYBERSECURITY OPERATIONS From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture byArielle Waldman AUG 6, 2026 4 MIN READ APPLICATION SECURITY Microsoft's Patch Tuesday Deluge Continues With August Updates byJai Vijayan AUG 11, 2026 4 MIN READ CYBERATTACKS & DATA BREACHES Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition byRobert Lemos AUG 12, 2026 4 MIN READ Want more Dark Reading stories in your Google search results? LOADING... Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article