< Back to all clusters
[TECHNOLOGY] · UN · 9 sources

started · updated

Evooo1Bot Linux botnet turns edge devices into SOCKS5 proxies

Cybersecurity researchers have identified a new Linux botnet family known as Evooo1Bot. The malware utilizes core functionality from the leaked Mirai botnet source code but introduces advanced capabilities, such as encrypted command-and-control (C2) communications, an SSH brute-force scanner, and a SOCKS relay module that turns infected edge devices into SOCKS5 proxies.

Evooo1Bot has reportedly been active since July 2026, targeting internet-facing devices by exploiting various known vulnerabilities in hardware from manufacturers including Netgear, D-Link, Tenda, and Mitsubishi Electric. The botnet is notably sophisticated in its evasion techniques; it includes an SSH scanner that checks for the presence of honeypots like Cowrie or Kippo by inspecting SSH banners and specific file system paths. If a honeypot is detected, the botnet silently skips the target to avoid analysis.

To maintain persistence, the malware can prevent system reboots from interrupting its operation by keeping the /dev/watchdog open. The infection process involves a loader shell script that attempts to download various binary versions of the botnet using tools like wget, curl, or tftp, depending on the device's available resources.

Entities

Evooo1Bot · Evooo1Bot · FortiGuard Labs · Fortinet · Fortinet FortiGuard Labs · Linux · Mirai