V-Help
← All news
Security

New Evooo1Bot Botnet Targets Linux Devices, Turning Them Into Proxy Nodes

New Evooo1Bot Botnet Targets Linux Devices, Turning Them Into Proxy Nodes

Photo: BleepingComputer

Quick answer

Evooo1Bot is a new Mirai-based botnet attacking Linux devices via known vulnerabilities. It converts infected devices into proxy nodes for traffic relay, steals credentials, performs brute-force attacks, and supports 16…

Fortinet researchers have identified a new threat to Linux devices—the Evooo1Bot botnet, built on the Mirai source code. The malware targets routers, network gateways, and other internet-connected devices, exploiting known vulnerabilities in equipment from manufacturers such as Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The botnet’s primary activity has been observed since July of this year.

Evooo1Bot is not limited to traffic proxying. Its arsenal includes modules for credential theft, brute-force SSH attacks, and distributed DDoS attacks. The botnet uses encrypted communication channels with command servers via port 443 and performs thorough environment checks for debugging tools, virtual machines, and sandboxes to evade detection.

Infection occurs through vulnerabilities in devices, after which the malware downloads the appropriate version for the processor architecture. To ensure persistence, Evooo1Bot leverages system mechanisms such as systemd and cron, while also clearing command history to conceal attack traces. The botnet supports an interactive shell for remote control, and its SOCKS5 module allows attackers to mask traffic or bypass geographic restrictions.

Additionally, Evooo1Bot includes a credential-stealing module that monitors network connections and attempts to intercept HTTP authentication headers and cookies. The SSH scanner module uses 150 login and password combinations targeting corporate accounts and performs additional checks to avoid honeypot traps. The DDoS module, inherited from Mirai, supports 16 attack methods, including UDP, DNS, SYN, ACK, and HTTP floods.

Experts recommend updating device firmware, replacing default credentials, disabling remote management panels, and promptly replacing unsupported equipment to minimize infection risks.

Common questions

Which devices does the Evooo1Bot botnet target?
Evooo1Bot targets routers, network gateways, and other Linux-based devices from manufacturers such as Alcatel, NETGEAR, Tenda, Mitsubishi Electric, D-Link, Hikvision, Zyxel, and others. Attacks exploit known vulnerabilities in these devices.
What functionalities does Evooo1Bot have?
The botnet can turn infected devices into proxy nodes for traffic relay, steal credentials, perform brute-force SSH attacks, and launch DDoS attacks using 16 different methods.
How can I protect against Evooo1Bot?
To mitigate risks, update device firmware, replace default credentials, disable remote access, and replace outdated equipment that is no longer supported by the manufacturer.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer