Evooo1Bot is a new Mirai-based modular Linux botnet that targets internet-facing gateway devices to turn them into SOCKS5 relay nodes while also enabling credential theft, SSH brute-forcing, and DDoS attacks. It has been observed exploiting multiple known vulnerabilities across devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, and other platforms, with newer builds targeting Hikvision, Confluence, Zyxel, TP-Link, WSO2, Kubernetes ingress-nginx, and PHP-CGI systems. #Evooo1Bot #Mirai #Alcatel #NETGEAR #Tenda #MitsubishiElectric #Telesquare #DLink #Hikvision #AtlassianConfluence #Zyxel #TPLink #WSO2 #Kubernetes #ingress-nginx #PHP-CGI
Keypoints
- Evooo1Bot is a Mirai-based modular botnet for Linux devices.
- It turns infected gateways into SOCKS5 traffic relay nodes.
- It can steal credentials, brute-force SSH, and launch DDoS attacks.
- It targets many devices and services by exploiting known vulnerabilities.
- It uses encrypted C2, persistence methods, and anti-analysis checks to stay hidden.