Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 9 sources · 18 days · First seen · Last updated
Mirai-derived Linux botnet activity
Overview
Researchers have identified new Mirai-derived Linux botnets targeting internet-facing edge devices.
In late July 2026, the Tengu botnet was disclosed. It utilizes Telnet credential brute-forcing to gain access and employs a hardware watchdog timer to ensure persistence by rebooting devices if its main process is killed. Tengu supports 25 DDoS methods and can function as a SOCKS5 proxy.
By mid-August 2026, a similar botnet family named Evooo1Bot was identified. Active since July 2026, Evooo1Bot targets hardware from manufacturers such as Netgear, D-Link, Tenda, and Mitsubishi Electric. Like Tengu, it uses a SOCKS5 relay module and maintains persistence by keeping the /dev/watchdog open. Evooo1Bot features advanced evasion techniques, including an SSH scanner designed to detect and skip honeypots like Cowrie or Kippo.
Entities
Fortinet · Mirai · Tengu botnet · Telnet protocol · Mirai botnet
Timeline
-
28 days ago
[TECHNOLOGY] 9 sourcesEvooo1Bot Linux botnet turns edge devices into SOCKS5 proxiesResearchers have discovered Evooo1Bot, a Linux botnet that exploits known vulnerabilities to turn edge devices into SOCKS5 proxies while using advanced techniques to evade security honeypots.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesTengu Botnet Exploits Linux Watchdog to Persist and Launch DDoS AttacksThe Tengu botnet, a Mirai‑derived threat, hijacks Linux devices by abusing hardware watchdogs, uses Telnet brute‑force for entry, and launches up to 25 DDoS attacks via a SOCKS5 proxy and payload downloads.
Sources
blogspan.net · cybernoz.com · imtest.de · it-boltwise.de · netzwelt.de · techjunkies.blog · technologyreview.de · truthtube.com · zehn.de