Infosecurity-Magazine Evooo1Bot: New Mirai-Based Linux Botnet Exploiting Edge Devices
Article Content
- •Evooo1Bot exploits multiple vulnerabilities in Linux edge devices since July 2026.
- •The botnet uses a loader script to download and execute malware, turning devices into proxies.
- •It features advanced capabilities, including encrypted communications and credential sniffing.
FortiGuard Labs has identified a new Linux botnet named Evooo1Bot, which is based on the Mirai malware framework. This botnet targets internet-facing edge devices, exploiting multiple vulnerabilities since July 2026. The botnet utilizes a loader script at 91.92.40[.]118/wget.sh to download and execute its payloads. Evooo1Bot incorporates advanced features such as encrypted C2 communications, an SSH brute-force scanner, and a SOCKS relay module that allows attackers to use compromised devices as proxies. The botnet's capabilities extend beyond conventional Mirai variants, posing a significant threat to organizations. Security researchers have observed targeted exploitation attempts across various regions, affecting any organization with vulnerable Linux systems. The botnet's modular architecture enables it to adapt and execute various commands based on the operator's needs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track Evooo1Bot and CVE-2007-3010 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft Patches Critical Vulnerabilities Amid Dropbox Account Breach Microsoft has released patches for nine vulnerabilities in various cloud services, including Entra ID and Azure Cosmos DB, requiring no action from users. In a separate incident, approximately 5,000 Dropbox accounts were compromised due to a flaw in Lenovo's email verification process, allowing attackers to access…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…