← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

New Mirai Variant "Evooo1Bot" Adds Stealth and Proxy Capabilities to Botnet Code

🔄 Updated 19h ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Evooo1Bot exploits vulnerabilities in routers and hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare.
  • It includes encrypted communications, SSH honeypot detection, and a credential sniffer.
  • The malware uses the SOCKS protocol to turn compromised devices into persistent proxies.
  • Activity is concentrated in North America, South America, Europe, India, China, and Japan.
  • Evooo1Bot is a Mirai-based botnet.
  • The botnet has been active since July.
  • Evooo1Bot can launch DDoS attacks.
  • Newer builds target Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and PHP-CGI installations.

Discovery of Evooo1Bot

Researchers at FortiGuard Labs have identified a new Mirai botnet variant, named Evooo1Bot, which has been actively exploiting vulnerabilities in internet-facing hardware for at least a month. This Linux-based malware targets routers and other devices from manufacturers including Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare. The malware spreads by exploiting unpatched bugs in these devices.

Advanced Stealth and Functionality

Evooo1Bot introduces several advanced capabilities beyond the typical distributed denial-of-service (DDoS) functions of Mirai. These include encrypted communications with command-and-control servers, a scanner that avoids SSH honeypots, and a sniffer designed to find default access credentials. FortiGuard Labs notes that these features elevate Evooo1Bot beyond the technical baseline of conventional Mirai-derived malware.

SOCKS Proxy for Concealment

A significant new feature is the malware's abuse of the SOCKS protocol. This allows Evooo1Bot to transform compromised routers, firewalls, IP cameras, or other edge devices into persistent proxies. This capability enables attackers to hide their true origin, penetrate internal networks, and conduct follow-on operations using the victim's infrastructure, making it harder to trace malicious activity.

Global Reach and Mirai's Legacy

While the exact number of compromised devices is not specified, FortiGuard Labs' telemetry indicates Evooo1Bot activity across North America, South America, Europe, India, China, and Japan. The Mirai source code, released in 2016, has consistently served as a foundation for numerous variants, with descendants like Aisuru and KimWolf recently targeted by law enforcement agencies.

Updates

🕒 2026-08-15 · new reporting from BleepingComputer
  • Evooo1Bot is a Mirai-based botnet.
  • The botnet has been active since July.
  • Evooo1Bot can launch DDoS attacks.
  • Newer builds target Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and PHP-CGI installations.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A new Mirai-based Linux botnet, Evooo1Bot, has been observed turning internet-facing gateway devices into SOCKS5 traffic relay nodes since July. This botnet expands on the original Mirai framework with capabilities like credential theft, SSH brute-forcing, and DDoS attacks, posing a threat to various network devices and potentially enabling further malicious activities.

A new Mirai botnet variant, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, according to FortiGuard Labs. This variant includes enhanced stealth features like SSH honeypot detection and a SOCKS proxy function, allowing attackers to conceal their origin and pivot into internal networks. The added capabilities make Evooo1Bot more sophisticated than previous Mirai-derived malware, posing a greater threat to network security.