Skip to content
Evooo1Bot: New Mirai-Based Linux Botnet Exploiting Edge Devices

Evooo1Bot: New Mirai-Based Linux Botnet Exploiting Edge Devices

First seen 14 Aug 2026, 13:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 15, 2026 at 12:07 UTC
  • •Evooo1Bot exploits multiple vulnerabilities in Linux edge devices since July 2026.
  • •The botnet uses a loader script to download and execute malware, turning devices into proxies.
  • •It features advanced capabilities, including encrypted communications and credential sniffing.

FortiGuard Labs has identified a new Linux botnet named Evooo1Bot, which is based on the Mirai malware framework. This botnet targets internet-facing edge devices, exploiting multiple vulnerabilities since July 2026. The botnet utilizes a loader script at 91.92.40[.]118/wget.sh to download and execute its payloads. Evooo1Bot incorporates advanced features such as encrypted C2 communications, an SSH brute-force scanner, and a SOCKS relay module that allows attackers to use compromised devices as proxies. The botnet's capabilities extend beyond conventional Mirai variants, posing a significant threat to organizations. Security researchers have observed targeted exploitation attempts across various regions, affecting any organization with vulnerable Linux systems. The botnet's modular architecture enables it to adapt and execute various commands based on the operator's needs.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 49d ago How this analysis works

Timeline

2007-09-18
CVE-2007-3010 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2020-07-13
CVE-2020-10987 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-06-02
CVE-2023-34362 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-04-03
Public exploit for CVE-2024-29269 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-07-01
Evooo1Bot begins targeting edge devices
The botnet has been actively exploiting vulnerabilities in Linux systems since July 2026.
Fortinet
2026-08-13
Evooo1Bot analysis published
FortiGuard Labs published a detailed analysis of Evooo1Bot, highlighting its capabilities and exploitation methods.
Fortinet
2026-08-14
Infosecurity Magazine reports on Evooo1Bot
Infosecurity Magazine reported on the new botnet, emphasizing its operational significance and modular design.
Infosecurity-Magazine

More articles in this cluster (17)

Following this threat?

Track Evooo1Bot and CVE-2007-3010 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed