Threat reportMalwareTL-2026-3062
Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices
Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet (TL-2026-3062), also tracked as Evooo1Bot, is a high-severity malware campaign, first published 2026-10-09. It has no confirmed attribution, affects Alcatel OmniPCX Enterprise, references 18 CVEs (CVE-2007-3010, CVE-2016-6277, CVE-2018-14558), maps to 17 MITRE ATT&CK techniques (T1027, T1036.004, T1037.004), and is covered by 9 detection rules and 12 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 18Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-3062
- Threat ID
- TL-2026-3062
- Also known as
- Evooo1Bot, evooo1, Linux/Agent.BDS!tr
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, technology, industrial, government administration, enterprise, consumer
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
Malware and tooling: Evooo1Bot, Mirai
How Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet works
FortiGuard Labs documents Evooo1Bot, a previously undocumented Linux botnet that reuses the leaked Mirai DDoS engine and adds encrypted C2, an SSH brute-force scanner, a SOCKS5 relay, an HTTP credential sniffer and an embedded exploit arsenal. It has targeted Internet-facing routers, cameras, NAS, firewalls and server software since July 2026.
Evooo1Bot (named for the hardcoded string "evooo1"; detected by Fortinet as Linux/Agent.BDS!tr) is a Linux botnet built on the publicly leaked Mirai source code. It keeps the Mirai DDoS engine (16 attack methods including UDP flood, VSE amplification, DNS flood, TCP SYN/ACK, STOMP, GRE-IP, GRE-Ethernet, XMAS, URG+SYN, fragmented TCP, OVH bypass and asynchronous SYN) but extends it into a general-purpose remote-access and proxy platform with 28 operator commands.
Initial access is by exploitation of known vulnerabilities in Internet-facing devices. C2 telemetry showed active exploitation of ten CVEs (Alcatel OmniPCX Enterprise CVE-2007-3010, NETGEAR CVE-2016-6277, Tenda CVE-2018-14558 and CVE-2020-10987, Mitsubishi Electric ME-RTU CVE-2019-14931, Telesquare CVE-2021-46422 and CVE-2024-29269, D-Link CVE-2022-37055, CVE-2025-10123 and CVE-2025-55583), all delivering payloads from the same loader URL 91.92.40.118/wget.sh. The sample additionally embeds an exploit table for eight more CVEs (Hikvision CVE-2021-36260, Atlassian Confluence CVE-2022-26134, Zyxel CVE-2022-30525, TP-Link Archer AX21 CVE-2023-1389, PHP-CGI CVE-2024-4577, D-Link NAS CVE-2024-10914, Kubernetes ingress-nginx CVE-2025-1974, WSO2 CVE-2022-29464), driven by the !cve, !stopcve and !cveall commands. Embedded campaign labels ("-s mitsu", "rep.alcatel") track Mitsubishi and Alcatel-Lucent targeting.
The loader script downloads one of 12 architecture-specific binaries using wget, busybox wget, curl or tftp (in fallback order) and clears shell history afterwards. Strings are protected with AES-256-CTR (60+ encrypted blocks) and ChaCha20, with 32-byte key constants split and recombined by XOR at runtime. C2 uses port 443. The bot checks for 40+ analysis tools on disk (strace, gdb, ghidra, ida, wireshark, tcpdump, volatility, etc.), a list of debugger/tracer process names, and sandbox/VM indicators (cuckoo, vmware, vbox, qemu, any.run, etc.).
Post-compromise functionality includes: an SSH brute-force scanner (banner SSH-2.0-OpenSSH_9.7p1, 150+ credentials including default IoT and enterprise service accounts such as jenkins, postgres, oracle, nagios, deploy) with honeypot detection (Cowrie, Kippo, paramiko, HonSSH, Glutton, OpenCanary and others, plus /opt/cowrie and /home/kippo filesystem checks); a SOCKS5 relay (default TCP 1080) that turns victims into proxies; a sniffer that reads /proc/net/tcp and intercepts HTTP Basic Auth; interactive shell/exec/stream commands; and file upload/download (10 MB limit, __FILE_START__/__FILE_END__ delimiters).
Persistence is layered: a systemd unit with Description=Apache HTTPD Cache Manager and Restart=always, a SysV init script, a */5 cron job that re-pulls the loader via wget/curl piped to sh, a script in /etc/profile.d/, an appended entry in /etc/rc.local, /proc/self/oom_score_adj tuning to avoid the OOM killer, and an open handle on /dev/watchdog to prevent reboots. No threat actor attribution is stated in the source.
MITRE ATT&CK techniques used in TL-2026-3062
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1070.003 Clear Command History; T1497.001 System Checks; T1622 Debugger Evasion
Persistence
T1037.004 RC Scripts; T1053.003 Cron; T1543.002 Systemd Service; T1546.004 Unix Shell Configuration Modification
Credential Access
T1040 Network Sniffing; T1110.001 Password Guessing
Execution
Command and Control
T1090 Proxy; T1573.001 Symmetric Cryptography
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1498.001 Direct Network Flood
Reconnaissance
Affected products and versions in Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
- Alcatel — OmniPCX Enterprise
Vulnerable versions: CVE-2007-3010 - NETGEAR — Multiple routers
Vulnerable versions: CVE-2016-6277 - Tenda — AC7/AC9/AC10 and AC1900 (AC15) routers
Vulnerable versions: CVE-2018-14558; CVE-2020-10987 - Mitsubishi Electric — ME-RTU
Vulnerable versions: CVE-2019-14931 - Telesquare — SDT-CW3B1 and TLR-2005KSH
Vulnerable versions: CVE-2021-46422; CVE-2024-29269 - D-Link — Multiple routers, DIR-823X, DIR-868L B1, NAS
Vulnerable versions: CVE-2022-37055; CVE-2025-10123; CVE-2025-55583; CVE-2024-10914 - Hikvision — IP cameras
Vulnerable versions: CVE-2021-36260 - Atlassian — Confluence
Vulnerable versions: CVE-2022-26134 - Zyxel — Firewalls
Vulnerable versions: CVE-2022-30525 - TP-Link — Archer AX21
Vulnerable versions: CVE-2023-1389
Remediation for Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
Patches
- Apply vendor fixes for all 18 exploited CVEs (Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, Hikvision, Atlassian, Zyxel, TP-Link, PHP, Kubernetes ingress-nginx, WSO2)
- Fortinet AV detection: Linux/Agent.BDS!tr
Immediate actions
- Block and alert on traffic to 91.92.40.118 (including TCP/443 and /wget.sh requests)
- Hunt for the systemd unit 'Apache HTTPD Cache Manager', unexpected /etc/profile.d/ scripts, /etc/rc.local additions and */5 cron entries piping wget/curl to sh
- Hunt for hashes f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109 and 4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d
- Isolate and reimage compromised edge devices; rotate all credentials that traversed them (HTTP Basic Auth may have been sniffed)
Workarounds
- Where no patch exists (e.g. end-of-life D-Link/Tenda/Telesquare devices), replace the device or place it behind a firewall with management access restricted to trusted networks
Longer-term hardening
- Remove management interfaces of routers, cameras, NAS and firewalls from the Internet
- Replace default and weak SSH credentials; restrict SSH exposure and use key-based authentication
- Retire end-of-life devices that can no longer be patched
- Monitor egress for unexpected SOCKS5 listeners (TCP 1080) and outbound DDoS-pattern traffic
CVEs associated with Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
Weaknesses (CWE) in Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
Timeline of Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
- Atlassian Confluence OGNL injection CVE-2022-26134, later embedded in Evooo1Bot's exploit table, is publicly disclosed
- PHP-CGI argument injection CVE-2024-4577, later embedded in Evooo1Bot's exploit table, is publicly disclosed
- Kubernetes ingress-nginx CVE-2025-1974, later embedded in Evooo1Bot's exploit table, is publicly disclosed
- FortiGuard C2 telemetry shows Evooo1Bot exploiting Internet-facing devices from July 2026 (month-level date), with all payload callbacks pointing at 91.92.40.118/wget.sh
- FortiGuard Labs publishes the first technical analysis of Evooo1Bot; Fortinet AV detects it as Linux/Agent.BDS!tr
- Secondary press coverage spreads (e.g. techora.ru); The Hacker News, Infosecurity Magazine, Dark Reading and SecPod also report on the botnet in August 2026
- Threadlinqs research completed; none of the 18 CVEs were found in the first 100KB of the CISA KEV catalog read (partial check, not conclusive); BeaconBeagle returned no record for 91.92.40.118
Sources cited for Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet
- Multi-Functional Linux Botnet "Evooo1Bot" (FortiGuard Labs)
- Evooo1Bot Linux Botnet Exploits Known Vulnerabilities (The Hacker News)
- New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies (Infosecurity Magazine)
- Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS (Dark Reading)
- Evooo1Bot Mirai-Based Linux Botnet Turns Edge Devices into SOCKS5 Proxies (SecPod)
- Evooo1Bot Linux Botnet Hijacks Routers and Firewalls (SOCRadar IOC Radar)
- ThreatFox IOC 1887006 (abuse.ch)
- NVD CVE-2025-1974 (ingress-nginx)
Detection coverage for TL-2026-3062
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3062 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3062
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.