Evooo1Bot multi-CVE exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Evooo1Bot has been actively exploiting internet-facing devices since July 2026, with a wave of attempts spanning multiple vulnerabilities across diverse regions. The activity broadens the risk to exposed edge devices by tying one loader infrastructure to many CVE hits.
Related Happenings
Evooo1Bot modular Linux botnet activity
Malware Activity
H score31
First: 14.08.2026 16:00
Last: 14.08.2026 16:00
Sources 1
How related:
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
About this happening:
Evooo1Bot, a new modular Linux botnet, is actively exploiting internet-facing edge devices and can convert them into proxies and botnet nodes. The malware is *...
Evooo1Bot modular Linux botnet activity
Malware ActivityHow related: A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
About this happening: Evooo1Bot, a new modular Linux botnet, is actively exploiting internet-facing edge devices and can convert them into proxies and botnet nodes. The malware is *...
IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)
Vulnerability
H score39
First: 18.03.2026 13:42
Last: 18.03.2026 13:42
Sources 1
About this happening:
Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...
IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...
AMD StackWarp SEV-SNP bypass (CVE-2025-29943)
Vulnerability
H score24
First: 19.01.2026 13:31
Last: 19.01.2026 13:31
Sources 1
About this happening:
StackWarp is a CVE-2025-29943 hardware vulnerability in AMD Zen 1 through Zen 5 CPUs that can bypass SEV-SNP protections and expose confidential VM workloads. The...
AMD StackWarp SEV-SNP bypass (CVE-2025-29943)
VulnerabilityAbout this happening: StackWarp is a CVE-2025-29943 hardware vulnerability in AMD Zen 1 through Zen 5 CPUs that can bypass SEV-SNP protections and expose confidential VM workloads. The...
Timeline
-
14.08.2026 16:00 2 articles · 1h ago
Evooo1Bot exploitation attempts hit edge devices through multiple CVEs
Initial DisclosureFortiGuard Labs researcher Yi Ping (Cara) Lin shared analysis of Evooo1Bot on August 13, identifying a Mirai-derived Linux botnet built from publicly leaked Mirai source code after observing exploitation attempts against edge devices. The activity mapped to multiple CVEs and all payload callbacks pointed to 91.92.40[.]118/wget.sh, while Lin assessed that the botnet has been actively targeting internet-facing devices since July 2026.
Show sources
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — www.infosecurity-magazine.com — 14.08.2026 16:00