Malware

Evooo1Bot Linux Botnet Exploits Routers

August 15, 2026 16:00 · 10 min read
Evooo1Bot Linux Botnet Exploits Routers

Evooo1Bot Linux Botnet: A New Threat to Internet-Facing Devices

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been discovered, targeting internet-facing gateway devices and turning them into SOCKS5 traffic relay nodes. According to Fortinet researchers, the malware's capabilities extend beyond proxying and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks.

Exploitation of Known Vulnerabilities

Evooo1Bot has been targeting devices from various manufacturers, including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, across different regions, by exploiting known vulnerabilities. The malware has been active since at least July, with its current geographical spread being tracked by Fortinet.

The malware reuses the DDoS engine from the publicly leaked Mirai source code but extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities.

Modular Architecture and Capabilities

Newer builds of Evooo1Bot include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, some of the embedded exploits are not correctly implemented, leading to failed exploitation.

When an exploit is successfully leveraged, a script downloads one of the 12 available malware builds that match the host's CPU architecture, then clears Bash history to wipe traces of the attack. Evooo1Bot uses encrypted command-and-control (C2) communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before launching on the infected device.

Persistence and Monetization

Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes. The malware features an interactive shell, giving operators direct control over compromised systems, and file-transfer commands supporting uploads and downloads.

A credential sniffer module monitors '/proc/net/tcp' and attempts to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems.

Defense and Prevention

To defend against botnet malware like Evooo1Bot, it is essential to keep IoT devices' firmware updated, replace default admin credentials, turn off remote access panels, and replace devices when the vendor no longer provides support for them. Once attackers have valid credentials, only 37% of their actions are blocked, highlighting the importance of overall prevention strategies.

According to The Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments, overall prevention scores can hide what happens after initial access. The report emphasizes the need for comprehensive security measures to prevent and mitigate the impact of botnet malware like Evooo1Bot.

By taking these steps, individuals and organizations can reduce the risk of falling victim to Evooo1Bot and other similar botnet malware, protecting their devices and networks from exploitation and malicious activities.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free