Evooo1Bot Hijacks Linux Devices for DDoS and Proxying


Evooo1Bot targets vulnerable Linux devices with DDoS, SSH attacks, credential sniffing and SOCKS5 proxy capabilities.

A new Linux botnet is targeting vulnerable internet-facing devices and giving its operators far more than a way to launch DDoS attacks.

Security researchers at FortiGuard Labs identified the malware, dubbed Evooo1Bot, which has been active since at least July. The botnet can compromise edge devices and use them for DDoS attacks, proxy traffic, scan for other systems and intercept authentication data.

Researchers say the malware borrows its DDoS engine from the leaked Mirai source code, but has been expanded with several additional capabilities.

Evooo1Bot is not relying on a single vulnerability to spread.

FortiGuard observed attacks against equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link.

Among the vulnerabilities seen in the captured attack traffic are CVE-2007-3010, affecting Alcatel OmniPCX Enterprise, CVE-2016-6277 in NETGEAR routers, CVE-2018-14558 affecting several Tenda routers and CVE-2019-14931, which affects Mitsubishi Electric Europe and INEA ME-RTU devices.

Researchers also saw attempts involving CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123 and CVE-2025-55583, affecting products from Tenda, Telesquare and D-Link.

Evooo1Bot also contains a separate HTTP exploit module with vulnerabilities affecting products and software from Hikvision, Atlassian, WSO2, Zyxel, TP-Link, PHP, D-Link and Kubernetes.

Once a vulnerable device is successfully exploited, the attackers use a shell script called wget.sh to download the malware.

The script determines which processor architecture the device uses and then retrieves the appropriate binary.

FortiGuard found the captured payloads pointing back to the same loader infrastructure. The malware also clears Bash history after execution, making some traces of the infection harder to recover.

After installation, Evooo1Bot checks its surroundings for tools commonly associated with malware analysis and debugging. Its communications with the command-and-control server are encrypted and use TCP port 443, helping the traffic blend in with ordinary web traffic.

One of the more interesting features is Evooo1Bot’s SOCKS5 relay.

An infected router, firewall, camera or other edge device can effectively become a proxy controlled by the attackers. Traffic can then be routed through the compromised system, making it appear to originate from the victim’s network.

That gives the operators another way to hide where their traffic is really coming from. FortiGuard also warned that compromised devices could potentially be used as a stepping stone into internal networks.

Evooo1Bot is also looking for its next victims.

Its SSH scanner uses a dictionary containing more than 150 credentials in an attempt to break into additional systems. FortiGuard also found checks intended to identify and avoid honeypots, suggesting the operators are taking steps to avoid attracting researchers’ attention.

The malware includes a network sniffer as well. It can capture HTTP Basic Authorization and Cookie headers, potentially exposing authentication information passing through an infected device.

Getting onto a device is only part of the operation. Evooo1Bot also has several ways to survive a reboot.

FortiGuard identified support for persistence through systemd, SysV init, cron, shell-profile injection and rc.local.

The malware’s command interface contains 28 commands, giving operators control over functions including file transfers, persistence, proxying, credential interception, SSH scanning, exploitation and DDoS attacks.

Its DDoS component is also extensive. Researchers identified 16 different flood methods, covering UDP, DNS and various TCP-based attacks.

Evooo1Bot may have started with pieces of Mirai, but it has evolved well beyond the original botnet’s basic formula.

Alongside DDoS functionality, it combines vulnerability exploitation, persistence, proxying, credential interception and SSH scanning in a single package.

The malware also uses several anti-analysis techniques, including AES-256-CTR, ChaCha20 and XOR-based protection, as well as checks for tools and environments commonly used by security researchers.

For organizations running internet-facing routers, cameras, firewalls and other edge equipment, the campaign is another reminder that old vulnerabilities can remain useful to attackers long after patches become available.

FortiGuard recommends keeping exposed devices and firmware up to date, monitoring unusual outbound connections and addressing vulnerable equipment before it can be pulled into the botnet.

Source: FortiGuard Labs

Related articles :


__Reports are sourced from official documents, law-enforcement updates, and credible investigations.

Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.__


readers loved this