Evooo1Bot modular Linux botnet activity
Malware Activity
Summary
Hide ▲
Show ▼
Evooo1Bot is a new modular Linux botnet that Fortinet says has been active since July 2026 and uses Mirai-derived code to compromise internet-facing edge devices. It combines encrypted C2 over port 443, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal against multiple known CVEs. The malware’s loader activity points to 91.92.40[.]118/wget.sh, and successful infections can turn affected devices into SOCKS5 proxies for relaying traffic and follow-on operations.
Related Happenings
Evooo1Bot multi-CVE exploitation wave
Exploitation Wave
H score1
First: 14.08.2026 16:00
Last: 14.08.2026 16:00
Sources 1
How related:
Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations.
About this happening:
Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions*...
Evooo1Bot multi-CVE exploitation wave
Exploitation WaveHow related: Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations.
About this happening: Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions*...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
C0XMO Gafgyt botnet activity on DD-WRT routers
Malware Activity
H score19
First: 07.06.2026 17:17
Last: 07.06.2026 17:17
Sources 1
About this happening:
The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...
C0XMO Gafgyt botnet activity on DD-WRT routers
Malware ActivityAbout this happening: The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
Vulnerability
H score1
First: 20.04.2026 16:01
Last: 20.04.2026 16:01
Sources 1
About this happening:
The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
VulnerabilityAbout this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
AVRecon malware for Linux powering SocksEscort proxy network
Malware Activity
H score19
First: 12.03.2026 18:19
Last: 12.03.2026 18:19
Sources 1
About this happening:
The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
AVRecon malware for Linux powering SocksEscort proxy network
Malware ActivityAbout this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...
Timeline
-
15.08.2026 17:14 2 articles · 12d ago
Evooo1Bot expands exploit arsenal against cameras, firewalls, and routers
Technical Analysis UpdateFortinet says Evooo1Bot targets internet-facing gateway devices and newer builds add an exploitation module for Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. The malware reuses the Mirai DDoS engine, uses encrypted C2 over port 443, includes an SSH brute-force scanner, a SOCKS relay module, and a credential sniffer that monitors /proc/net/tcp.
Show sources
- New Evooo1Bot Linux botnet turns routers into traffic relay nodes — www.bleepingcomputer.com — 15.08.2026 17:14
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies — thehackernews.com — 17.08.2026 12:29
-
14.08.2026 16:00 2 articles · 13d ago
Evooo1Bot modular Linux botnet activity
Initial DisclosureThe first observed phase centered on exploitation attempts against multiple edge-device vulnerabilities and download activity from 91.92.40[.]118/wget.sh. Analysis on August 13 tied the behavior to Evooo1Bot, which has been active since July 2026.
Show sources
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00