Find notable cyber news and cases, enriched with sources, timelines, and signals.

Evooo1Bot modular Linux botnet activity

Malware Activity
First reported
Last updated
Happening score
H score 33
3 unique sources, 3 articles

Summary

Hide ▲

Evooo1Bot is a new modular Linux botnet that Fortinet says has been active since July 2026 and uses Mirai-derived code to compromise internet-facing edge devices. It combines encrypted C2 over port 443, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal against multiple known CVEs. The malware’s loader activity points to 91.92.40[.]118/wget.sh, and successful infections can turn affected devices into SOCKS5 proxies for relaying traffic and follow-on operations.

Related Happenings

Evooo1Bot multi-CVE exploitation wave

Exploitation Wave
H score1 First: 14.08.2026 16:00 Last: 14.08.2026 16:00 Sources 1

How related: Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations.

About this happening: Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions*...

Foreign-run botnets relaying traffic through infected Canadian devices

Malware Activity
H score22 First: 22.06.2026 12:11 Last: 22.06.2026 12:11 Sources 1

About this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...

C0XMO Gafgyt botnet activity on DD-WRT routers

Malware Activity
H score19 First: 07.06.2026 17:17 Last: 07.06.2026 17:17 Sources 1

About this happening: The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...

TBK DVR command injection flaw actively exploited (CVE-2024-3721)

Vulnerability
H score1 First: 20.04.2026 16:01 Last: 20.04.2026 16:01 Sources 1

About this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...

AVRecon malware for Linux powering SocksEscort proxy network

Malware Activity
H score19 First: 12.03.2026 18:19 Last: 12.03.2026 18:19 Sources 1

About this happening: The AVRecon malware for Linux powered the SocksEscort proxy network, turning compromised Linux-based SOHO routers into traffic-routing nodes at scale. It was believed...

Timeline

  1. 15.08.2026 17:14 2 articles · 12d ago

    Evooo1Bot expands exploit arsenal against cameras, firewalls, and routers

    Technical Analysis Update

    Fortinet says Evooo1Bot targets internet-facing gateway devices and newer builds add an exploitation module for Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. The malware reuses the Mirai DDoS engine, uses encrypted C2 over port 443, includes an SSH brute-force scanner, a SOCKS relay module, and a credential sniffer that monitors /proc/net/tcp.

    Show sources
  2. 14.08.2026 16:00 2 articles · 13d ago

    Evooo1Bot modular Linux botnet activity

    Initial Disclosure

    The first observed phase centered on exploitation attempts against multiple edge-device vulnerabilities and download activity from 91.92.40[.]118/wget.sh. Analysis on August 13 tied the behavior to Evooo1Bot, which has been active since July 2026.

    Show sources