Evooo1Bot multi-CVE exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions. The activity broadens the risk to exposed edge devices by tying one loader infrastructure to many CVE hits.
Related Happenings
Evooo1Bot modular Linux botnet activity
Malware Activity
H score33
First: 14.08.2026 16:00
Last: 14.08.2026 16:00
Sources 1
How related:
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
About this happening:
Evooo1Bot is a new modular Linux botnet that Fortinet says has been active since July 2026 and uses Mirai-derived code to compromise internet-facing edge devices...
Evooo1Bot modular Linux botnet activity
Malware ActivityHow related: A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
About this happening: Evooo1Bot is a new modular Linux botnet that Fortinet says has been active since July 2026 and uses Mirai-derived code to compromise internet-facing edge devices...
Latest development: 15.08.2026 17:14
Fortinet says Evooo1Bot targets internet-facing gateway devices and newer builds add an exploitation module for Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. The malware reuses the Mirai DDoS engine, uses encrypted C2 over port 443, includes an SSH brute-force scanner, a SOCKS relay module, and a credential sniffer that monitors /proc/net/tcp.
UAT-7810 Operational Relay Box network-building campaign
Campaign
H score39
First: 08.07.2026 12:04
Last: 08.07.2026 12:04
Sources 1
About this happening:
An ongoing UAT-7810 campaign is expanding Operational Relay Box (ORB) networks by breaking into internet-facing networking devices, increasing relay capacity for downs...
UAT-7810 Operational Relay Box network-building campaign
CampaignAbout this happening: An ongoing UAT-7810 campaign is expanding Operational Relay Box (ORB) networks by breaking into internet-facing networking devices, increasing relay capacity for downs...
IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)
Vulnerability
H score39
First: 18.03.2026 13:42
Last: 18.03.2026 13:42
Sources 1
About this happening:
Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...
IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...
AMD StackWarp SEV-SNP bypass (CVE-2025-29943)
Vulnerability
H score24
First: 19.01.2026 13:31
Last: 19.01.2026 13:31
Sources 1
About this happening:
StackWarp is a CVE-2025-29943 hardware vulnerability in AMD Zen 1 through Zen 5 CPUs that can bypass SEV-SNP protections and expose confidential VM workloads. The...
AMD StackWarp SEV-SNP bypass (CVE-2025-29943)
VulnerabilityAbout this happening: StackWarp is a CVE-2025-29943 hardware vulnerability in AMD Zen 1 through Zen 5 CPUs that can bypass SEV-SNP protections and expose confidential VM workloads. The...
Timeline
-
14.08.2026 16:00 3 articles · 13d ago
Evooo1Bot exploitation attempts hit edge devices through multiple CVEs
Initial DisclosureFortiGuard Labs researcher Yi Ping (Cara) Lin shared analysis of Evooo1Bot on August 13, identifying a Mirai-derived Linux botnet built from publicly leaked Mirai source code after observing exploitation attempts against edge devices. The activity mapped to multiple CVEs and all payload callbacks pointed to 91.92.40[.]118/wget.sh, while Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026.
Show sources
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00
- New Evooo1Bot Linux botnet turns routers into traffic relay nodes — www.bleepingcomputer.com — 15.08.2026 17:14