Evooo1Bot modular Linux botnet activity
Malware Activity
Updated: 14.08.2026 16:00
· First: 14.08.2026 16:00
· 📰 2 src / 2 articles
· H score: 33
Evooo1Bot, a new modular Linux botnet, is actively exploiting internet-facing edge devices and can convert them into proxies and botnet nodes. The malware is Mirai-derived and adds encrypted C2, a 28-command remote administration interface, an SSH brute-force scanner, and a reverse SOCKS relay. Analysis linked the activity to multiple exploited CVEs and a shared loader URL at 91.92.40[.]118/wget.sh. The combination of exploitation and proxying raises the risk of stealthier follow-on access through compromised infrastructure.