Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
MessiahGPT AI Model Automates Ransomware and Phishing Attacks
August 17, 2026
Fake Web3 Interview Campaign Delivers NeedleStealer and hVNC RAT via Signed ClickOnce
August 17, 2026
New Windows Backdoor Hides C2 in desktop.ini Whitespace
August 17, 2026
Home/Threats/Evooo1Bot Linux Botnet Hijacks Edge Devices with 16 DDoS Methods and SOCKS5 Proxies
Threats

Evooo1Bot Linux Botnet Hijacks Edge Devices with 16 DDoS Methods and SOCKS5 Proxies

Key Takeaways A new Linux botnet, Evooo1Bot, is actively targeting internet-facing edge devices by exploiting known vulnerabilities and weak SSH credentials. The botnet leverages a multi-functional...

Emy Elsamnoudy
Emy Elsamnoudy
August 17, 2026 5 Min Read
2 0

Key Takeaways

  • A new Linux botnet, Evooo1Bot, is actively targeting internet-facing edge devices by exploiting known vulnerabilities and weak SSH credentials.
  • The botnet leverages a multi-functional design, incorporating elements from the Mirai framework, SOCKS5 proxy capabilities, credential sniffing, and a diverse exploit arsenal.
  • Evooo1Bot can launch 16 different types of DDoS attacks and utilizes compromised devices as SOCKS5 proxies, enabling attackers to conceal their origin and potentially gain deeper network access.
  • The threat highlights the critical need for robust cybersecurity hygiene, including prompt patching, strong authentication, and vigilant monitoring of outbound network traffic on edge devices.

A sophisticated Linux botnet, dubbed Evooo1Bot, has emerged, actively compromising internet-facing edge devices to enlist them in a range of malicious activities. This new threat is not merely a tool for denial-of-service attacks; it transforms infected systems into versatile instruments for remote access, traffic relaying, and further exploitation, according to research by Fortinet.

Table Of Content

  • Key Takeaways
  • Advanced Attack Capabilities
  • Sixteen DDoS Methods Expand the Threat
  • SOCKS5 Proxies Turn Victims Into Relays
  • What You Should Do

Evooo1Bot infiltrates vulnerable edge infrastructure by exploiting identified security flaws and attempting brute-force attacks against weak SSH credentials. Once established, the botnet enables its operators to issue commands via an encrypted control channel, significantly expanding the scope of potential damage beyond traditional DDoS operations.

Analysts at Fortinet said in a report that their telemetry data indicates Evooo1Bot has been targeting edge devices since July 2026, with campaigns often categorized by the specific vulnerabilities leveraged. This multi-faceted approach, combining code from the notorious Mirai framework with proxy functionalities, credential harvesting, file transfer capabilities, and an exploit module, reflects a growing trend in botnet evolution towards broader and more complex abuse scenarios.

The danger posed by an Evooo1Bot infection extends far beyond a device simply going offline. A compromised system can be weaponized for attacks against other targets, used to mask an attacker’s true location, or serve as a critical pivot point for deeper penetration into an organization’s internal network. This reinforces the urgent need for organizations to prioritize the security of their edge devices, especially those that are directly exposed to the internet and remain unpatched.

Advanced Attack Capabilities

Sixteen DDoS Methods Expand the Threat

Evooo1Bot is equipped with an impressive array of 16 distinct traffic-flooding methods, including UDP, DNS, SYN, GRE, and fragmented TCP attacks. While its core DDoS engine bears structural similarities to the leaked Mirai code, Evooo1Bot introduces enhanced flexibility. Its HTTP flood function, for instance, allows operators to specify custom request methods, headers, and expected values. This adaptability helps malicious traffic appear less uniform, complicating detection and mitigation efforts during an active attack.

The botnet also features an exploit dispatcher designed to deliver payloads by exploiting known vulnerabilities in products from various vendors, including D-Link, Tenda, Hikvision, Zyxel, and TP-Link. Although some listed exploits may not be fully functional, this extensive list provides operators with a broad testing ground for potential targets. This capability underscores the critical importance of consistent and timely patching practices for network devices to curb the spread and growth of such botnets.

Upon successful compromise, a loader script fetches the appropriate binary for the victim’s processor architecture, executes it temporarily, and then clears the Bash history to obscure its presence. For persistence, the malware can establish itself through various mechanisms, including system services, startup scripts, scheduled tasks, shell profiles, and rc.local. To evade detection, Evooo1Bot performs checks for analysis tools, sandboxes, virtual machines, and containers before initiating a connection to its command-and-control server on port 443.

The primary concern for defenders lies in the potential for scale. Each compromised appliance contributes to the botnet’s overall attack capacity and introduces new potential entry points into networks. Implementing prompt firmware updates, minimizing unnecessary public exposure, utilizing strong and unique administrative credentials, and actively monitoring for unusual outbound connections are fundamental steps to mitigate this escalating threat.

SOCKS5 Proxies Turn Victims Into Relays

A key feature that distinguishes Evooo1Bot beyond its DDoS capabilities is its integrated SOCKS relay module. In its “direct” operational mode, the bot can open a SOCKS5 listener, typically on TCP port 1080. Alternatively, in “reverse” mode, the bot establishes encrypted outbound connections to an operator-controlled relay server. This allows traffic to be routed through the victimized device without exposing a listener to the internet, significantly enhancing the attackers’ stealth.

This SOCKS5 proxy functionality enables threat actors to conceal the true origin of their malicious activities, bypass geographical access controls, and establish a clandestine pathway into networks shielded by the compromised device. The prevalence of similar SOCKS5 proxy abuse tactics highlights why security teams must interpret unexplained proxy behavior as a significant intrusion indicator, rather than dismissing it as a minor network anomaly.

Evooo1Bot further incorporates an SSH scanner equipped with over 150 embedded credentials, including common service-account names found in enterprise environments. The botnet attempts to evade honeypots by examining SSH banners and verifying successful targets for signs of emulation. Additionally, a separate sniffer module can harvest HTTP Basic Authorization and Cookie headers, dramatically increasing the potential impact and cost of an infection.

What You Should Do

  • Inventory and Secure Edge Devices: Conduct a thorough inventory of all internet-exposed equipment. Ensure remote management interfaces are disabled if not strictly necessary.
  • Patch Promptly: Apply vendor firmware updates and security patches immediately upon release to address known vulnerabilities that Evooo1Bot exploits.
  • Strengthen Credentials: Enforce strong, unique administrative credentials for all devices. Avoid default or weak passwords. Implement multi-factor authentication where possible.
  • Monitor Outbound Connections: Vigilantly monitor for unusual outbound encrypted sessions originating from edge appliances, especially those that typically do not initiate such connections.
  • Detect Anomalous Proxy Behavior: Treat any unexplained SOCKS listeners or proxy activity as a critical intrusion signal and investigate immediately.
  • Review Scheduled Tasks and Downloads: Monitor for unexpected scheduled downloads or the creation of new scheduled tasks on your devices.
  • Block Known Indicators of Compromise (IoCs): Configure firewalls, intrusion detection/prevention systems (IDS/IPS), and other security controls to block traffic to and from the following IoCs:
    • IP address: 91.92.40[.]118 (Command-and-control infrastructure and loader host)
    • URL: http://91.92.40[.]118/wget.sh (Loader URL)
    • File name: wget.sh (Loader script)
    • SHA-256 hashes: f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109, 4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d

    Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarePatchSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

SafePal Confirms Data Breach Exposing Customer Order Information

Next Post

ChainDrop npm Worm Compromises 444 Packages via GitHub Actions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
SafePal Confirms Data Breach Exposing Customer Order Information
August 17, 2026
Critical Outlook RCE, Palo Alto, Cisco, Windows Zero-Days Exposed
August 17, 2026
Critical Apple Screen Sharing Flaw Lets Attackers Execute Commands as Root
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us