Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
The Evooo1Bot is a multi-functional Linux botnet that turns compromised devices into SOCKS5 relays, SSH spreaders, and DDoS tools. Created by FortiGuard Labs in 2026, it appears as a variant of Mirai and can target various Linux gateways using over 150 credential combinations. These devices include routers, firewalls, IP cameras, and more.
Evooo1Bot exploits publicly exposed devices by sending exploit requests for known vulnerabilities. If successful, it downloads and installs a payload tailored to the device's CPU architecture. This payload provides 12 different CPU architecture support and is capable of executing various malicious activities, such as encrypted C2 communications, credential sniffing, SSH spreading, persistence, and multiple types of DDoS attacks.
The attack flow consists of four stages. In the first stage, the attacker exploits public devices by sending vulnerability exploits. If successful, the loader connects to the C2 server and waits for commands. The second stage involves evading analysis and establishing C2 by decrypting strings, checking for analysis tools or sandboxes, and connecting to an encrypted C2 server.
In the third stage, the bot spreads via SSH credential attacks, checking SSH banners and trying to log in using over 150 username and password combinations. Finally, in the fourth stage, Post-compromise actions include using persistence mechanisms, relaying traffic via SOCKS, running sniffers, conducting DDoS attacks, scanning for additional devices, and delivering the same loader to vulnerable entry points.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.