Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

A new Linux botnet has emerged, threatening organizations with capabilities that go far beyond traditional distributed denial of service (DDoS) attacks. The botnet, dubbed Evooo1Bot by researchers at Fortiguard Labs, is built on top of the Mirai malware framework but adds a range of new features to turn compromised devices into persistent attacker infrastructure.

Evooo1Bot has been targeting Linux systems since at least July, exploiting vulnerabilities in various internet-facing devices from manufacturers such as Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The botnet reuses the Mirai DDoS engine but adds a host of new capabilities, including encrypted command-and-control (C2) communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities.

According to Fortiguard Labs threat researcher Cara Lin, Evooo1Bot’s capabilities are significantly more advanced than those of its Mirai-based counterparts. The botnet can establish encrypted C2 communications over TCP port 442, execute commands, and maintain persistence through various mechanisms. It also attempts to detect analysis tools, virtualized environments, and honeypots before proceeding.

One of the most notable features of Evooo1Bot is its reverse SOCKS relay module, which allows attackers to route subsequent traffic through the victim’s own network. This provides cover for a range of additional malicious activities, including pivoting into internal networks and conducting follow-on operations through the victim’s infrastructure.

While previous Mirai-based botnets have also incorporated activity beyond DDoS into their arsenals, Evooo1Bot’s reverse SOCKS relay module is a significant advancement that enables attackers to conceal their true origin and conduct more sophisticated attacks. According to Waseem Ahmed, head of engineering at Secure.com, this feature sets Evooo1Bot apart from other post-Mirai botnets.

“Evooo1Bot doesn’t just add more firepower to knock a target offline,” Ahmed notes. “It brute-forces SSH with a list of enterprise-focused logins, exploits a long list of known bugs in routers, cameras, and firewalls, and then turns the compromised device into a hidden SOCKS proxy the attacker can route traffic through.”

The emergence of Evooo1Bot highlights the ongoing threat posed by Mirai-derived malware. While these botnets often rely on exploiting old vulnerabilities that remain unpatched on devices, they continue to evolve and add new capabilities. This demonstrates how attackers don’t need cutting-edge exploits to threaten organizations but instead can target forgotten, unpatched devices.

Organizations must therefore take steps to protect themselves from this type of threat. This includes ensuring that all internet-facing devices are up-to-date with the latest security patches, monitoring for signs of compromise, and implementing robust C2 detection and mitigation measures. By taking these precautions, organizations can reduce their risk of falling victim to Evooo1Bot or other Mirai-derived malware.

In practical terms, this means that IT teams should prioritize patch management, regularly scan devices for vulnerabilities, and implement additional security controls such as intrusion prevention systems (IPS) and C2 detection tools. By staying vigilant and proactive, organizations can minimize their exposure to the threat posed by Evooo1Bot and other Mirai-derived malware.


Source: Dark Reading — 2026-08-17