HomeRisk ManagementsNew Mirai-Based Linux Botnet Evooo1Bot Converts Victims Into Proxies

New Mirai-Based Linux Botnet Evooo1Bot Converts Victims Into Proxies

Published on

spot_img

A recent analysis has brought attention to a new modular Linux botnet family, referred to as ‘Evooo1Bot,’ which has emerged from the publicly leaked source code of the notorious Mirai botnet. The research, conducted by Yi Ping (Cara) Lin, a Taiwan-based security expert at Fortinet’s FortiGuard Labs, was released on August 13. The name ‘Evooo1Bot’ is derived from the hardcoded string ‘evooo1’ found in every binary associated with the botnet.

Evooo1Bot has been notably linked to exploitation attempts targeting several vulnerabilities in various edge devices. These vulnerabilities span a range of devices and include:

  • CVE-2007-3010: This vulnerability is associated with remote code execution (RCE) issues in Alcatel’s OmniPCX Enterprise systems.
  • CVE-2016-6277: This pertains to RCE vulnerabilities in multiple NETGEAR routers.
  • CVE-2018-14558: Found in Tenda’s AC7, AC9, and AC10 routers, this vulnerability involves command injection issues.
  • CVE-2019-14931: This vulnerability impacts Mitsubishi Electric Europe and INEA ME-RTU devices through remote command injection.
  • CVE-2020-10987: This RCE vulnerability is identified in the Tenda AC1900 Router AC15 model.
  • CVE-2021-46422: This relates to command injection vulnerabilities in Telesquare’s SDT-CW3B1 devices.
  • CVE-2022-37055: Found in D-Link routers, this vulnerability involves buffer overflow issues.
  • CVE-2024-29269: This addresses command injection vulnerabilities in Telesquare TLR-2005KSH devices.
  • CVE-2025-10123: This relates to command injection vulnerabilities found in the D-Link DIR-823X router.
  • CVE-2025-55583: This vulnerability, also in D-Link routers, involves command injection in the DIR-868L B1 model.

All exploitation attempts linked to these vulnerabilities have consistently pointed to a common loader URL at 91.92.40[.]118/wget.sh, which is associated with Evooo1Bot. Lin estimated that this botnet has been actively targeting internet-facing devices since July 2026, showcasing a significant reach across various regions.

Evooo1Bot: An Advanced Version of Mirai

Evooo1Bot distinguishes itself by reusing critical components of the distributed denial-of-service (DDoS) architecture from the Mirai botnet. Mirai has gained notoriety as a malware strain that primarily targets Internet of Things (IoT) devices through the use of default credentials, transforming them into vast networks—botnets—that can execute extensive DDoS attacks.

The root of Mirai’s influence traces back to September 2016 when its source code was leaked on the online platform Hack Forums by a user known as “Anna-senpai.” This individual was later revealed by the FBI to be college student Paras Jha, alongside his co-creators Josiah White and Dalton Norman. Initially designed to attack Minecraft servers and offer DDoS protection services, the release of the source code created an avalanche effect, leading to the emergence of numerous modern malware variants that continue to exploit the Mirai DDoS engine.

While Evooo1Bot is built on the same technological framework as Mirai, Lin notes that its developers have significantly expanded its capabilities. The new botnet includes:

  • Encrypted command-and-control (C2) communications along with a 28-command remote administration interface.
  • An SSH brute-force scanner to gain unauthorized access.
  • A reverse SOCKS relay module, which is vital for operational capabilities.
  • Several layers of string obfuscation utilizing advanced cryptographic methods like AES-256-CTR, ChaCha20, and XOR-based key derivation.
  • An integrated credential sniffer to capture authentication information.
  • A comprehensive exploit arsenal designed to target known vulnerabilities across IoT devices, networking equipment, and enterprise applications.

Lin emphasized the significance of the SOCKS relay module, deeming it “arguably the most operationally significant aspect” of Evooo1Bot. This feature enables compromised edge devices to function as persistent proxies, allowing attackers to mask their true origin while gaining access to internal networks. This capability facilitates follow-on operations through the victim’s infrastructure, elevating the threat level posed by Evooo1Bot significantly.

In conclusion, Evooo1Bot represents a worrying evolution in the landscape of botnets, surpassing previous models like Mirai with its extensive functionality and operational sophistication. As it continues to exploit various vulnerabilities, it highlights the urgent need for heightened security measures in protecting edge devices across the digital landscape.

Source link

Latest articles

Laundry Bear Uses Zimbra Zero-Click Vulnerability to Steal 90 Days’ Worth of Emails

Russian Hacking Campaign Unveiled: A Wake-Up Call for Cybersecurity A recent warning issued by the...

How CSOs Can Transform Cybersecurity into a Business Growth Strategy

Integrating Security into Business Operations: A Strategic Approach In today's rapidly evolving technological landscape, it...

ERP Security Challenges in Keeping Up with AI Agents

Agentic AI, Application Security, ...

The 80% Problem: The Rising Importance of AI Resilience

AI has undoubtedly transformed the landscape of the workplace, significantly enhancing efficiency by automating...

More like this

Laundry Bear Uses Zimbra Zero-Click Vulnerability to Steal 90 Days’ Worth of Emails

Russian Hacking Campaign Unveiled: A Wake-Up Call for Cybersecurity A recent warning issued by the...

How CSOs Can Transform Cybersecurity into a Business Growth Strategy

Integrating Security into Business Operations: A Strategic Approach In today's rapidly evolving technological landscape, it...

ERP Security Challenges in Keeping Up with AI Agents

Agentic AI, Application Security, ...