# Mirai-derived Linux botnet activity

> Live situation record from CLSTR: https://clstr.news/situations/mirai-derived-linux-botnet-activity
> Updated: 2026-08-15T15:45:50.000Z. Sources: 9. Developments: 2.

Researchers have identified new Mirai-derived Linux botnets targeting internet-facing edge devices. 

In late July 2026, the Tengu botnet was disclosed. It utilizes Telnet credential brute-forcing to gain access and employs a hardware watchdog timer to ensure persistence by rebooting devices if its main process is killed. Tengu supports 25 DDoS methods and can function as a SOCKS5 proxy.

By mid-August 2026, a similar botnet family named Evooo1Bot was identified. Active since July 2026, Evooo1Bot targets hardware from manufacturers such as Netgear, D-Link, Tenda, and Mitsubishi Electric. Like Tengu, it uses a SOCKS5 relay module and maintains persistence by keeping the /dev/watchdog open. Evooo1Bot features advanced evasion techniques, including an SSH scanner designed to detect and skip honeypots like Cowrie or Kippo.

## Timeline

### 2026-08-15: Evooo1Bot Linux botnet turns edge devices into SOCKS5 proxies

Researchers have discovered Evooo1Bot, a Linux botnet that exploits known vulnerabilities to turn edge devices into SOCKS5 proxies while using advanced techniques to evade security honeypots.

9 sources. https://clstr.news/cluster/evooo1bot-linux-botnet-targets-routers-to-create-socks5-proxies

### 2026-07-28: Tengu Botnet Exploits Linux Watchdog to Persist and Launch DDoS Attacks

The Tengu botnet, a Mirai‑derived threat, hijacks Linux devices by abusing hardware watchdogs, uses Telnet brute‑force for entry, and launches up to 25 DDoS attacks via a SOCKS5 proxy and payload downloads.

2 sources. https://clstr.news/cluster/tengu-botnet-exploits-linux-watchdog-to-persist-and-launch-ddos-attacks

---
Cite as: Mirai-derived Linux botnet activity. CLSTR, https://clstr.news/situations/mirai-derived-linux-botnet-activity
