CyberSecurity SEE

New Mirai-Based Linux Botnet Evooo1Bot Converts Victims Into Proxies

New Mirai-Based Linux Botnet Evooo1Bot Converts Victims Into Proxies

A recent analysis has brought attention to a new modular Linux botnet family, referred to as ‘Evooo1Bot,’ which has emerged from the publicly leaked source code of the notorious Mirai botnet. The research, conducted by Yi Ping (Cara) Lin, a Taiwan-based security expert at Fortinet’s FortiGuard Labs, was released on August 13. The name ‘Evooo1Bot’ is derived from the hardcoded string ‘evooo1’ found in every binary associated with the botnet.

Evooo1Bot has been notably linked to exploitation attempts targeting several vulnerabilities in various edge devices. These vulnerabilities span a range of devices and include:

All exploitation attempts linked to these vulnerabilities have consistently pointed to a common loader URL at 91.92.40[.]118/wget.sh, which is associated with Evooo1Bot. Lin estimated that this botnet has been actively targeting internet-facing devices since July 2026, showcasing a significant reach across various regions.

Evooo1Bot: An Advanced Version of Mirai

Evooo1Bot distinguishes itself by reusing critical components of the distributed denial-of-service (DDoS) architecture from the Mirai botnet. Mirai has gained notoriety as a malware strain that primarily targets Internet of Things (IoT) devices through the use of default credentials, transforming them into vast networks—botnets—that can execute extensive DDoS attacks.

The root of Mirai’s influence traces back to September 2016 when its source code was leaked on the online platform Hack Forums by a user known as “Anna-senpai.” This individual was later revealed by the FBI to be college student Paras Jha, alongside his co-creators Josiah White and Dalton Norman. Initially designed to attack Minecraft servers and offer DDoS protection services, the release of the source code created an avalanche effect, leading to the emergence of numerous modern malware variants that continue to exploit the Mirai DDoS engine.

While Evooo1Bot is built on the same technological framework as Mirai, Lin notes that its developers have significantly expanded its capabilities. The new botnet includes:

Lin emphasized the significance of the SOCKS relay module, deeming it “arguably the most operationally significant aspect” of Evooo1Bot. This feature enables compromised edge devices to function as persistent proxies, allowing attackers to mask their true origin while gaining access to internal networks. This capability facilitates follow-on operations through the victim’s infrastructure, elevating the threat level posed by Evooo1Bot significantly.

In conclusion, Evooo1Bot represents a worrying evolution in the landscape of botnets, surpassing previous models like Mirai with its extensive functionality and operational sophistication. As it continues to exploit various vulnerabilities, it highlights the urgent need for heightened security measures in protecting edge devices across the digital landscape.

Source link

Exit mobile version