Find notable cyber news and cases, enriched with sources, timelines, and signals.

Evooo1Bot modular Linux botnet activity

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

Evooo1Bot, a new modular Linux botnet, is actively exploiting internet-facing edge devices and can convert them into proxies and botnet nodes. The malware is Mirai-derived and adds encrypted C2, a 28-command remote administration interface, an SSH brute-force scanner, and a reverse SOCKS relay. Analysis linked the activity to multiple exploited CVEs and a shared loader URL at 91.92.40[.]118/wget.sh. The combination of exploitation and proxying raises the risk of stealthier follow-on access through compromised infrastructure.

Related Happenings

Evooo1Bot multi-CVE exploitation wave

Exploitation Wave
H score1 First: 14.08.2026 16:00 Last: 14.08.2026 16:00 Sources 1

How related: Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions.

About this happening: Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions*...

Foreign-run botnets relaying traffic through infected Canadian devices

Malware Activity
H score22 First: 22.06.2026 12:11 Last: 22.06.2026 12:11 Sources 1

About this happening: The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, governm...

C0XMO Gafgyt botnet activity on DD-WRT routers

Malware Activity
H score19 First: 07.06.2026 17:17 Last: 07.06.2026 17:17 Sources 1

About this happening: The C0XMO botnet is spreading through DD-WRT router firmware and other internet-facing devices, increasing the pool of systems available for DDoS attacks. It exploits...

TBK DVR command injection flaw actively exploited (CVE-2024-3721)

Vulnerability
H score1 First: 20.04.2026 16:01 Last: 20.04.2026 16:01 Sources 1

About this happening: The CVE-2024-3721 command injection flaw in TBK DVR systems is being actively exploited to gain access and install Nexcorium malware. Attackers abuse crafted request...

Timeline

  1. 14.08.2026 16:00 2 articles · 1h ago

    Evooo1Bot modular Linux botnet activity

    Initial Disclosure

    The first observed phase centered on exploitation attempts against multiple edge-device vulnerabilities and download activity from 91.92.40[.]118/wget.sh. Analysis on August 13 tied the behavior to Evooo1Bot, which has been active since July 2026.

    Show sources