Evooo1Bot Linux Botnet Hijacks Edge Devices with 16 DDoS Methods and SOCKS5 Proxies
Key Takeaways A new Linux botnet, Evooo1Bot, is actively targeting internet-facing edge devices by exploiting known vulnerabilities and weak SSH credentials. The botnet leverages a multi-functional...
Key Takeaways
- A new Linux botnet, Evooo1Bot, is actively targeting internet-facing edge devices by exploiting known vulnerabilities and weak SSH credentials.
- The botnet leverages a multi-functional design, incorporating elements from the Mirai framework, SOCKS5 proxy capabilities, credential sniffing, and a diverse exploit arsenal.
- Evooo1Bot can launch 16 different types of DDoS attacks and utilizes compromised devices as SOCKS5 proxies, enabling attackers to conceal their origin and potentially gain deeper network access.
- The threat highlights the critical need for robust cybersecurity hygiene, including prompt patching, strong authentication, and vigilant monitoring of outbound network traffic on edge devices.
A sophisticated Linux botnet, dubbed Evooo1Bot, has emerged, actively compromising internet-facing edge devices to enlist them in a range of malicious activities. This new threat is not merely a tool for denial-of-service attacks; it transforms infected systems into versatile instruments for remote access, traffic relaying, and further exploitation, according to research by Fortinet.
Table Of Content
Evooo1Bot infiltrates vulnerable edge infrastructure by exploiting identified security flaws and attempting brute-force attacks against weak SSH credentials. Once established, the botnet enables its operators to issue commands via an encrypted control channel, significantly expanding the scope of potential damage beyond traditional DDoS operations.
Analysts at Fortinet said in a report that their telemetry data indicates Evooo1Bot has been targeting edge devices since July 2026, with campaigns often categorized by the specific vulnerabilities leveraged. This multi-faceted approach, combining code from the notorious Mirai framework with proxy functionalities, credential harvesting, file transfer capabilities, and an exploit module, reflects a growing trend in botnet evolution towards broader and more complex abuse scenarios.
The danger posed by an Evooo1Bot infection extends far beyond a device simply going offline. A compromised system can be weaponized for attacks against other targets, used to mask an attacker’s true location, or serve as a critical pivot point for deeper penetration into an organization’s internal network. This reinforces the urgent need for organizations to prioritize the security of their edge devices, especially those that are directly exposed to the internet and remain unpatched.
Advanced Attack Capabilities
Sixteen DDoS Methods Expand the Threat
Evooo1Bot is equipped with an impressive array of 16 distinct traffic-flooding methods, including UDP, DNS, SYN, GRE, and fragmented TCP attacks. While its core DDoS engine bears structural similarities to the leaked Mirai code, Evooo1Bot introduces enhanced flexibility. Its HTTP flood function, for instance, allows operators to specify custom request methods, headers, and expected values. This adaptability helps malicious traffic appear less uniform, complicating detection and mitigation efforts during an active attack.
The botnet also features an exploit dispatcher designed to deliver payloads by exploiting known vulnerabilities in products from various vendors, including D-Link, Tenda, Hikvision, Zyxel, and TP-Link. Although some listed exploits may not be fully functional, this extensive list provides operators with a broad testing ground for potential targets. This capability underscores the critical importance of consistent and timely patching practices for network devices to curb the spread and growth of such botnets.
Upon successful compromise, a loader script fetches the appropriate binary for the victim’s processor architecture, executes it temporarily, and then clears the Bash history to obscure its presence. For persistence, the malware can establish itself through various mechanisms, including system services, startup scripts, scheduled tasks, shell profiles, and rc.local. To evade detection, Evooo1Bot performs checks for analysis tools, sandboxes, virtual machines, and containers before initiating a connection to its command-and-control server on port 443.
The primary concern for defenders lies in the potential for scale. Each compromised appliance contributes to the botnet’s overall attack capacity and introduces new potential entry points into networks. Implementing prompt firmware updates, minimizing unnecessary public exposure, utilizing strong and unique administrative credentials, and actively monitoring for unusual outbound connections are fundamental steps to mitigate this escalating threat.
SOCKS5 Proxies Turn Victims Into Relays
A key feature that distinguishes Evooo1Bot beyond its DDoS capabilities is its integrated SOCKS relay module. In its “direct” operational mode, the bot can open a SOCKS5 listener, typically on TCP port 1080. Alternatively, in “reverse” mode, the bot establishes encrypted outbound connections to an operator-controlled relay server. This allows traffic to be routed through the victimized device without exposing a listener to the internet, significantly enhancing the attackers’ stealth.
This SOCKS5 proxy functionality enables threat actors to conceal the true origin of their malicious activities, bypass geographical access controls, and establish a clandestine pathway into networks shielded by the compromised device. The prevalence of similar SOCKS5 proxy abuse tactics highlights why security teams must interpret unexplained proxy behavior as a significant intrusion indicator, rather than dismissing it as a minor network anomaly.
Evooo1Bot further incorporates an SSH scanner equipped with over 150 embedded credentials, including common service-account names found in enterprise environments. The botnet attempts to evade honeypots by examining SSH banners and verifying successful targets for signs of emulation. Additionally, a separate sniffer module can harvest HTTP Basic Authorization and Cookie headers, dramatically increasing the potential impact and cost of an infection.
What You Should Do
- Inventory and Secure Edge Devices: Conduct a thorough inventory of all internet-exposed equipment. Ensure remote management interfaces are disabled if not strictly necessary.
- Patch Promptly: Apply vendor firmware updates and security patches immediately upon release to address known vulnerabilities that Evooo1Bot exploits.
- Strengthen Credentials: Enforce strong, unique administrative credentials for all devices. Avoid default or weak passwords. Implement multi-factor authentication where possible.
- Monitor Outbound Connections: Vigilantly monitor for unusual outbound encrypted sessions originating from edge appliances, especially those that typically do not initiate such connections.
- Detect Anomalous Proxy Behavior: Treat any unexplained SOCKS listeners or proxy activity as a critical intrusion signal and investigate immediately.
- Review Scheduled Tasks and Downloads: Monitor for unexpected scheduled downloads or the creation of new scheduled tasks on your devices.
- Block Known Indicators of Compromise (IoCs): Configure firewalls, intrusion detection/prevention systems (IDS/IPS), and other security controls to block traffic to and from the following IoCs:
- IP address:
91.92.40[.]118(Command-and-control infrastructure and loader host) - URL:
http://91.92.40[.]118/wget.sh(Loader URL) - File name:
wget.sh(Loader script) - SHA-256 hashes:
f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109,4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d
Note: IP addresses and domains are intentionally defanged (e.g.,
[.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM. - IP address:
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.