# Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices

> FortiGuard Labs documents Evooo1Bot, a previously undocumented Linux botnet that reuses the leaked Mirai DDoS engine and adds encrypted C2, an SSH brute-force scanner, a SOCKS5 relay, an HTTP credential sniffer and an embedded exploit arsenal. It has targeted Internet-facing routers, cameras, NAS, firewalls and server software since July 2026.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3062
- **ID:** TL-2026-3062
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583, CVE-2021-36260, CVE-2022-26134, CVE-2022-30525, CVE-2023-1389, CVE-2024-4577, CVE-2024-10914, CVE-2025-1974, CVE-2022-29464

## Description

Evooo1Bot (named for the hardcoded string "evooo1"; detected by Fortinet as Linux/Agent.BDS!tr) is a Linux botnet built on the publicly leaked Mirai source code. It keeps the Mirai DDoS engine (16 attack methods including UDP flood, VSE amplification, DNS flood, TCP SYN/ACK, STOMP, GRE-IP, GRE-Ethernet, XMAS, URG+SYN, fragmented TCP, OVH bypass and asynchronous SYN) but extends it into a general-purpose remote-access and proxy platform with 28 operator commands.

Initial access is by exploitation of known vulnerabilities in Internet-facing devices. C2 telemetry showed active exploitation of ten CVEs (Alcatel OmniPCX Enterprise CVE-2007-3010, NETGEAR CVE-2016-6277, Tenda CVE-2018-14558 and CVE-2020-10987, Mitsubishi Electric ME-RTU CVE-2019-14931, Telesquare CVE-2021-46422 and CVE-2024-29269, D-Link CVE-2022-37055, CVE-2025-10123 and CVE-2025-55583), all delivering payloads from the same loader URL 91.92.40.118/wget.sh. The sample additionally embeds an exploit table for eight more CVEs (Hikvision CVE-2021-36260, Atlassian Confluence CVE-2022-26134, Zyxel CVE-2022-30525, TP-Link Archer AX21 CVE-2023-1389, PHP-CGI CVE-2024-4577, D-Link NAS CVE-2024-10914, Kubernetes ingress-nginx CVE-2025-1974, WSO2 CVE-2022-29464), driven by the !cve, !stopcve and !cveall commands. Embedded campaign labels ("-s mitsu", "rep.alcatel") track Mitsubishi and Alcatel-Lucent targeting.

The loader script downloads one of 12 architecture-specific binaries using wget, busybox wget, curl or tftp (in fallback order) and clears shell history afterwards. Strings are protected with AES-256-CTR (60+ encrypted blocks) and ChaCha20, with 32-byte key constants split and recombined by XOR at runtime. C2 uses port 443. The bot checks for 40+ analysis tools on disk (strace, gdb, ghidra, ida, wireshark, tcpdump, volatility, etc.), a list of debugger/tracer process names, and sandbox/VM indicators (cuckoo, vmware, vbox, qemu, any.run, etc.).

Post-compromise functionality includes: an SSH brute-force scanner (banner SSH-2.0-OpenSSH_9.7p1, 150+ credentials including default IoT and enterprise service accounts such as jenkins, postgres, oracle, nagios, deploy) with honeypot detection (Cowrie, Kippo, paramiko, HonSSH, Glutton, OpenCanary and others, plus /opt/cowrie and /home/kippo filesystem checks); a SOCKS5 relay (default TCP 1080) that turns victims into proxies; a sniffer that reads /proc/net/tcp and intercepts HTTP Basic Auth; interactive shell/exec/stream commands; and file upload/download (10 MB limit, __FILE_START__/__FILE_END__ delimiters).

Persistence is layered: a systemd unit with Description=Apache HTTPD Cache Manager and Restart=always, a SysV init script, a */5 cron job that re-pulls the loader via wget/curl piped to sh, a script in /etc/profile.d/, an appended entry in /etc/rc.local, /proc/self/oom_score_adj tuning to avoid the OOM killer, and an open handle on /dev/watchdog to prevent reboots. No threat actor attribution is stated in the source.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1059.004 Unix Shell
- T1053.003 Cron
- T1543.002 Systemd Service
- T1037.004 RC Scripts
- T1546.004 Unix Shell Configuration Modification
- T1036.004 Masquerade Task or Service
- T1027 Obfuscated Files or Information
- T1070.003 Clear Command History
- T1497.001 System Checks
- T1622 Debugger Evasion
- T1110.001 Password Guessing
- T1040 Network Sniffing
- T1090 Proxy
- T1573.001 Symmetric Cryptography
- T1498.001 Direct Network Flood

## Sources

- [Multi-Functional Linux Botnet "Evooo1Bot" (FortiGuard Labs)](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)
- [Evooo1Bot Linux Botnet Exploits Known Vulnerabilities (The Hacker News)](https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html)
- [New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/)
- [Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS (Dark Reading)](https://darkreading.com/cyber-risk/linux-botnet-evooo1bot-mirai-capabilities-beyond-ddos)
- [Evooo1Bot Mirai-Based Linux Botnet Turns Edge Devices into SOCKS5 Proxies (SecPod)](https://www.secpod.com/learn/security-research/evooo1-bot-mirai-based-linux-botnet-turns-edge-devices-into-socks-5-proxies)
- [Evooo1Bot Linux Botnet Hijacks Routers and Firewalls (SOCRadar IOC Radar)](https://socradar.io/free-tools/ioc-radar/reports/evooo1bot-linux-botnet-hijacks-routers-and-firewalls-for-ddos-socks5-proxy-and-credential-theft-3d22f8ff2c78)
- [ThreatFox IOC 1887006 (abuse.ch)](https://threatfox.abuse.ch/ioc/1887006/json/)
- [NVD CVE-2025-1974 (ingress-nginx)](https://nvd.nist.gov/vuln/detail/CVE-2025-1974)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3062
