Evooo1Bot: A Multi-Functional Linux Botnet That Turns Compromised Gateways into SOCKS5 Relays, SSH Spreaders, and DDoS Tools
Evooo1Bot: A Multi-Functional Linux Botnet That Turns Compromised Gateways into SOCKS5 Relays, SSH Spreaders, and DDoS Tools 1. Basic Information Severity: High Title: Multi-Functional Linux Botnet “Evooo1Bot” Publisher: FortiGuard Labs Release Date: 2026-08-13 Update Date: None Original Source: FortiGuard Labs Related Sources: BleepingComputer , The Record Malware: Evooo1Bot, Mirai variant…
The Evooo1Bot is a multi-functional Linux botnet that utilizes publicly exposed devices with known vulnerabilities and various credential combinations to infect and compromise Linux gateways. Once compromised, the botnet can deploy payloads that support 12 CPU architectures, utilizing encrypted C2 communications, SOCKS5 relaying, credential sniffing, SSH spreading, persistence, and 16 types of DDoS attacks.
The attack flow chain consists of four stages: exploiting publicly exposed devices, evading analysis and establishing C2, spreading via SSH credential attacks, and post-compromise relaying, persistence, and attacks.
Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.