Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
FortiGuard Labs has identified a new Mirai-derived Linux botnet named Evooo1Bot that is actively targeting internet-facing hardware from manufacturers including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The malware leverages a wide array of historical vulnerabilities, spanning from CVE-2007-3010 to CVE-2020-10987, to gain initial access and deploy a modular framework that goes far beyond standard DDoS attacks. Notably, the botnet includes an SSH brute-force scanner, credential sniffing capabilities, and a reverse SOCKS relay module that allows attackers to use compromised edge devices as stealthy proxies for further network infiltration. This evolution highlights the growing sophistication of Mirai-based threats, turning simple flood tools into comprehensive attack platforms that exploit even years-old unpatched software.