Threat reportMalwareTL-2026-3062

Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices

highACTIVE

Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet (TL-2026-3062), also tracked as Evooo1Bot, is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Alcatel OmniPCX Enterprise, references 18 CVEs (CVE-2007-3010, CVE-2016-6277, CVE-2018-14558), maps to 17 MITRE ATT&CK techniques (T1027, T1036.004, T1037.004), and is covered by 9 detection rules and 12 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
18Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-3062

Threat ID
TL-2026-3062
Also known as
Evooo1Bot, evooo1, Linux/Agent.BDS!tr
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, technology, industrial, government administration, enterprise, consumer
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

Malware and tooling: Evooo1Bot, Mirai

How Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet works

FortiGuard Labs documents Evooo1Bot, a previously undocumented Linux botnet that reuses the leaked Mirai DDoS engine and adds encrypted C2, an SSH brute-force scanner, a SOCKS5 relay, an HTTP credential sniffer and an embedded exploit arsenal. It has targeted Internet-facing routers, cameras, NAS, firewalls and server software since July 2026.

Evooo1Bot (named for the hardcoded string "evooo1"; detected by Fortinet as Linux/Agent.BDS!tr) is a Linux botnet built on the publicly leaked Mirai source code. It keeps the Mirai DDoS engine (16 attack methods including UDP flood, VSE amplification, DNS flood, TCP SYN/ACK, STOMP, GRE-IP, GRE-Ethernet, XMAS, URG+SYN, fragmented TCP, OVH bypass and asynchronous SYN) but extends it into a general-purpose remote-access and proxy platform with 28 operator commands.

Initial access is by exploitation of known vulnerabilities in Internet-facing devices. C2 telemetry showed active exploitation of ten CVEs (Alcatel OmniPCX Enterprise CVE-2007-3010, NETGEAR CVE-2016-6277, Tenda CVE-2018-14558 and CVE-2020-10987, Mitsubishi Electric ME-RTU CVE-2019-14931, Telesquare CVE-2021-46422 and CVE-2024-29269, D-Link CVE-2022-37055, CVE-2025-10123 and CVE-2025-55583), all delivering payloads from the same loader URL 91.92.40.118/wget.sh. The sample additionally embeds an exploit table for eight more CVEs (Hikvision CVE-2021-36260, Atlassian Confluence CVE-2022-26134, Zyxel CVE-2022-30525, TP-Link Archer AX21 CVE-2023-1389, PHP-CGI CVE-2024-4577, D-Link NAS CVE-2024-10914, Kubernetes ingress-nginx CVE-2025-1974, WSO2 CVE-2022-29464), driven by the !cve, !stopcve and !cveall commands. Embedded campaign labels ("-s mitsu", "rep.alcatel") track Mitsubishi and Alcatel-Lucent targeting.

The loader script downloads one of 12 architecture-specific binaries using wget, busybox wget, curl or tftp (in fallback order) and clears shell history afterwards. Strings are protected with AES-256-CTR (60+ encrypted blocks) and ChaCha20, with 32-byte key constants split and recombined by XOR at runtime. C2 uses port 443. The bot checks for 40+ analysis tools on disk (strace, gdb, ghidra, ida, wireshark, tcpdump, volatility, etc.), a list of debugger/tracer process names, and sandbox/VM indicators (cuckoo, vmware, vbox, qemu, any.run, etc.).

Post-compromise functionality includes: an SSH brute-force scanner (banner SSH-2.0-OpenSSH_9.7p1, 150+ credentials including default IoT and enterprise service accounts such as jenkins, postgres, oracle, nagios, deploy) with honeypot detection (Cowrie, Kippo, paramiko, HonSSH, Glutton, OpenCanary and others, plus /opt/cowrie and /home/kippo filesystem checks); a SOCKS5 relay (default TCP 1080) that turns victims into proxies; a sniffer that reads /proc/net/tcp and intercepts HTTP Basic Auth; interactive shell/exec/stream commands; and file upload/download (10 MB limit, __FILE_START__/__FILE_END__ delimiters).

Persistence is layered: a systemd unit with Description=Apache HTTPD Cache Manager and Restart=always, a SysV init script, a */5 cron job that re-pulls the loader via wget/curl piped to sh, a script in /etc/profile.d/, an appended entry in /etc/rc.local, /proc/self/oom_score_adj tuning to avoid the OOM killer, and an open handle on /dev/watchdog to prevent reboots. No threat actor attribution is stated in the source.

MITRE ATT&CK techniques used in TL-2026-3062

Defense Evasion

T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1070.003 Clear Command History; T1497.001 System Checks; T1622 Debugger Evasion

Persistence

T1037.004 RC Scripts; T1053.003 Cron; T1543.002 Systemd Service; T1546.004 Unix Shell Configuration Modification

Credential Access

T1040 Network Sniffing; T1110.001 Password Guessing

Execution

T1059.004 Unix Shell

Command and Control

T1090 Proxy; T1573.001 Symmetric Cryptography

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1498.001 Direct Network Flood

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

  • Alcatel — OmniPCX Enterprise
    Vulnerable versions: CVE-2007-3010
  • NETGEAR — Multiple routers
    Vulnerable versions: CVE-2016-6277
  • Tenda — AC7/AC9/AC10 and AC1900 (AC15) routers
    Vulnerable versions: CVE-2018-14558; CVE-2020-10987
  • Mitsubishi Electric — ME-RTU
    Vulnerable versions: CVE-2019-14931
  • Telesquare — SDT-CW3B1 and TLR-2005KSH
    Vulnerable versions: CVE-2021-46422; CVE-2024-29269
  • D-Link — Multiple routers, DIR-823X, DIR-868L B1, NAS
    Vulnerable versions: CVE-2022-37055; CVE-2025-10123; CVE-2025-55583; CVE-2024-10914
  • Hikvision — IP cameras
    Vulnerable versions: CVE-2021-36260
  • Atlassian — Confluence
    Vulnerable versions: CVE-2022-26134
  • Zyxel — Firewalls
    Vulnerable versions: CVE-2022-30525
  • TP-Link — Archer AX21
    Vulnerable versions: CVE-2023-1389

Remediation for Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

Patches

  • Apply vendor fixes for all 18 exploited CVEs (Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, Hikvision, Atlassian, Zyxel, TP-Link, PHP, Kubernetes ingress-nginx, WSO2)
  • Fortinet AV detection: Linux/Agent.BDS!tr

Immediate actions

  • Block and alert on traffic to 91.92.40.118 (including TCP/443 and /wget.sh requests)
  • Hunt for the systemd unit 'Apache HTTPD Cache Manager', unexpected /etc/profile.d/ scripts, /etc/rc.local additions and */5 cron entries piping wget/curl to sh
  • Hunt for hashes f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109 and 4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d
  • Isolate and reimage compromised edge devices; rotate all credentials that traversed them (HTTP Basic Auth may have been sniffed)

Workarounds

  • Where no patch exists (e.g. end-of-life D-Link/Tenda/Telesquare devices), replace the device or place it behind a firewall with management access restricted to trusted networks

Longer-term hardening

  • Remove management interfaces of routers, cameras, NAS and firewalls from the Internet
  • Replace default and weak SSH credentials; restrict SSH exposure and use key-based authentication
  • Retire end-of-life devices that can no longer be patched
  • Monitor egress for unexpected SOCKS5 listeners (TCP 1080) and outbound DDoS-pattern traffic

CVEs associated with Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

Weaknesses (CWE) in Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

CWE-78, CWE-120, CWE-798

Timeline of Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

  • Atlassian Confluence OGNL injection CVE-2022-26134, later embedded in Evooo1Bot's exploit table, is publicly disclosed
  • PHP-CGI argument injection CVE-2024-4577, later embedded in Evooo1Bot's exploit table, is publicly disclosed
  • Kubernetes ingress-nginx CVE-2025-1974, later embedded in Evooo1Bot's exploit table, is publicly disclosed
  • FortiGuard C2 telemetry shows Evooo1Bot exploiting Internet-facing devices from July 2026 (month-level date), with all payload callbacks pointing at 91.92.40.118/wget.sh
  • FortiGuard Labs publishes the first technical analysis of Evooo1Bot; Fortinet AV detects it as Linux/Agent.BDS!tr
  • Secondary press coverage spreads (e.g. techora.ru); The Hacker News, Infosecurity Magazine, Dark Reading and SecPod also report on the botnet in August 2026
  • Threadlinqs research completed; none of the 18 CVEs were found in the first 100KB of the CISA KEV catalog read (partial check, not conclusive); BeaconBeagle returned no record for 91.92.40.118

Sources cited for Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet

Detection coverage for TL-2026-3062

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3062 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3062

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats