Back Infosecurity-Magazine New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin, shared an analysis of the new botnet family on August 13, which she called ‘Evooo1Bot’ after the hardcoded string ‘evooo1’ found in every binary.
The botnet was discovered after observed exploitation of the following vulnerabilities:
All payload callbacks for these exploitation attempts pointed to the same loader URL at 91.92.40[.]118/wget.sh, linked to Evooo1Bot.
Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.
Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from the Mirai source code.
Mirai is a notorious malware strain that infects internet-of-things (IoT) devices using default credentials, turning them into a massive networks – a botnet – to launch DDoS attacks.
Its source code was publicly leaked in September 2016 on Hack Forums by user ‘Anna-senpai,’ later unmasked by the FBI as college student Paras Jha along with co-creators Josiah White and Dalton Norman.
Originally built to target Minecraft servers and sell DDoS-protection services, the creators released the code to flood the web with noise and obscure their identities as law enforcement closed in, inadvertently spawning countless modern malware variants that continue to reuse Mirai's DDoS engine today.
Despite working from the Mirai framework , the developers of Evooo1Bot have significantly extended their malware with numerous capabilities, including:
Lin highlighted that the SOCKS relay module is “arguably the most operationally significant” as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.
“These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” Lin wrote.
Read now: New Mirai Botnet Exploits Zero-Days in Routers and Smart Devices
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
