< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 9 sources · 18 days · First seen · Last updated

Mirai-derived Linux botnet activity

Overview

Researchers have identified new Mirai-derived Linux botnets targeting internet-facing edge devices.

In late July 2026, the Tengu botnet was disclosed. It utilizes Telnet credential brute-forcing to gain access and employs a hardware watchdog timer to ensure persistence by rebooting devices if its main process is killed. Tengu supports 25 DDoS methods and can function as a SOCKS5 proxy.

By mid-August 2026, a similar botnet family named Evooo1Bot was identified. Active since July 2026, Evooo1Bot targets hardware from manufacturers such as Netgear, D-Link, Tenda, and Mitsubishi Electric. Like Tengu, it uses a SOCKS5 relay module and maintains persistence by keeping the /dev/watchdog open. Evooo1Bot features advanced evasion techniques, including an SSH scanner designed to detect and skip honeypots like Cowrie or Kippo.

Entities

Fortinet · Mirai · Tengu botnet · Telnet protocol · Mirai botnet

Timeline

  1. 28 days ago

    [TECHNOLOGY] 9 sources
    Evooo1Bot Linux botnet turns edge devices into SOCKS5 proxies

    Researchers have discovered Evooo1Bot, a Linux botnet that exploits known vulnerabilities to turn edge devices into SOCKS5 proxies while using advanced techniques to evade security honeypots.

  2. about 2 months ago

    [TECHNOLOGY] 2 sources
    Tengu Botnet Exploits Linux Watchdog to Persist and Launch DDoS Attacks

    The Tengu botnet, a Mirai‑derived threat, hijacks Linux devices by abusing hardware watchdogs, uses Telnet brute‑force for entry, and launches up to 25 DDoS attacks via a SOCKS5 proxy and payload downloads.

Sources

blogspan.net · cybernoz.com · imtest.de · it-boltwise.de · netzwelt.de · techjunkies.blog · technologyreview.de · truthtube.com · zehn.de