Evooo1Bot modular Linux botnet activity
Malware Activity
Summary
Hide ▲
Show ▼
Evooo1Bot, a new modular Linux botnet, is actively exploiting internet-facing edge devices and can convert them into proxies and botnet nodes. The malware is Mirai-derived and adds encrypted C2, a 28-command remote administration interface, an SSH brute-force scanner, and a reverse SOCKS relay. Analysis linked the activity to multiple exploited CVEs and a shared loader URL at 91.92.40[.]118/wget.sh. The combination of exploitation and proxying raises the risk of stealthier follow-on access through compromised infrastructure.
Related Happenings
Evooo1Bot multi-CVE exploitation wave
Exploitation Wave
H score1
First: 14.08.2026 16:00
Last: 14.08.2026 16:00
Sources 1
How related:
Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.
About this happening:
Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions*...
Evooo1Bot multi-CVE exploitation wave
Exploitation WaveHow related: Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.
About this happening: Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions*...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
H score22
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
About this happening:
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
Foreign-run botnets relaying traffic through infected Canadian devices
Malware ActivityAbout this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...
C0XMO Gafgyt botnet activity on DD-WRT routers
Malware Activity
H score19
First: 07.06.2026 17:17
Last: 07.06.2026 17:17
Sources 1
About this happening:
The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...
C0XMO Gafgyt botnet activity on DD-WRT routers
Malware ActivityAbout this happening: The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
Vulnerability
H score1
First: 20.04.2026 16:01
Last: 20.04.2026 16:01
Sources 1
About this happening:
The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
TBK DVR command injection flaw actively exploited (CVE-2024-3721)
VulnerabilityAbout this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...
Timeline
-
14.08.2026 16:00 2 articles · 1h ago
Evooo1Bot modular Linux botnet activity
Initial DisclosureThe first observed phase centered on exploitation attempts against multiple edge-device vulnerabilities and download activity from 91.92.40[.]118/wget.sh. Analysis on August 13 tied the behavior to Evooo1Bot, which has been active since July 2026.
Show sources
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00