Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

A Highly Capable Linux Botnet Has Emerged, Threatening Internet-Facing Devices Worldwide

A new Linux botnet, dubbed Evooo1Bot by researchers at FortiGuard Labs, has been wreaking havoc on the cybersecurity landscape. This highly capable malware family combines the Mirai distributed denial-of-service (DDoS) engine with a range of malicious capabilities that go far beyond traditional DDoS attacks.

Evooo1Bot targets Linux-based systems, primarily Internet-facing devices such as routers and IP cameras from various manufacturers like Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The malware exploits a wide range of vulnerabilities, some dating back to 2007, including command injection and remote code execution bugs.

The researchers at FortiGuard Labs discovered Evooo1Bot through their intrusion prevention system (IPS) telemetry, which revealed exploitation activity targeting edge devices with payload callbacks pointing to the same loader URL. Once installed, the malware establishes encrypted command-and-control (C2) communications over TCP port 442 and executes commands to maintain persistence.

What sets Evooo1Bot apart from its Mirai-derived predecessors is its modular framework and multifunctional capabilities. The botnet includes modules for credential theft, reverse SOCKS relays, and an integrated exploit arsenal targeting multiple known vulnerabilities. This advanced functionality allows attackers to not only knock targets offline but also pivot into internal networks and conduct follow-on operations through the victim’s infrastructure.

The most significant aspect of Evooo1Bot is its ability to transform compromised devices into persistent proxies for routing traffic and concealing the attacker’s origin. This is a game-changer in the world of malware, as it provides attackers with unprecedented flexibility and stealth.

“It extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” said Cara Lin, threat researcher at FortiGuard Labs. “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware.”

The emergence of Evooo1Bot highlights the ongoing threat posed by botnets to organizations worldwide. It’s a stark reminder that attackers don’t need cutting-edge exploits to cause significant harm; they can target forgotten, unpatched devices carrying old vulnerabilities.

In light of this development, it’s essential for organizations to prioritize patch management and vulnerability remediation. They should also implement robust security measures, such as intrusion detection systems (IDS) and IPS, to detect and prevent the spread of malware like Evooo1Bot.

As Waseem Ahmed, head of engineering at Secure.com, notes, “Organizations need to be aware that DDoS attacks are no longer just about knocking targets offline. They can now pivot into internal networks and conduct follow-on operations through the victim’s infrastructure.”


Source: Dark Reading — 2026-08-17