Published Security3 min read
Evooo1Bot turns edge devices into proxies, and most of its exploits predate 2023
Fortinet's analysis of a new Mirai derivative lists ten CVEs; seven carry identifiers from 2007 to 2022. The reverse SOCKS relay is the part operators should read twice.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
- Yi Ping (Cara) Lin, a Taiwan-based security researcher at Fortinet's FortiGuard Labs, shared an analysis of the new botnet family on August 13, calling it 'Evooo1Bot' after the hardcoded string 'evooo1' found in every binary.
- Evooo1Bot reuses the distributed denial-of-service engine from the Mirai source code.
- Lin highlighted that the SOCKS relay module is "arguably the most operationally significant" capability, as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.
- The pre-2023 vulnerabilities observed being exploited were: CVE-2007-3010 (Alcatel OmniPCX Enterprise RCE), CVE-2016-6277 (NETGEAR multiple routers RCE), CVE-2018-14558 (Tenda AC7/AC9/AC10 command injection), CVE-2019-14931 (Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU remote command injection), CVE-2020-10987 (Tenda AC1900 Router AC15 RCE), CVE-2021-46422 (Telesquare SDT-CW3B1 command injection) and CVE-2022-37055 (D-Link routers buffer overflow).
Compiled by The WatchSomething wrong?How this is made
Why it matters
Fortinet's FortiGuard Labs has tied a run of edge-device exploitation attempts to a new modular Linux botnet family built on the leaked Mirai source code, named Evooo1Bot after the hardcoded string "evooo1" found in every binary [1][2]. The DDoS engine is inherited and unremarkable [3]; the reverse SOCKS relay module, which turns each compromised router into a persistent proxy for its operator, is not [4][9].
The target list is the part worth sitting with. Of the ten vulnerabilities Yi Ping (Cara) Lin observed being exploited, seven carry identifiers from 2007 through 2022 [5][6][13]. The oldest, CVE-2007-3010 in Alcatel OmniPCX Enterprise, is eighteen years older than the newest entries on the list [5][6][15]. In between sit NETGEAR, Tenda, Telesquare and D-Link consumer routers, plus CVE-2019-14931, a remote command injection affecting Mitsubishi Electric Europe and INEA ME-RTU devices, which puts remote terminal units in the same scan queue as home broadband gear [5]. D-Link alone accounts for three of the ten [5][6][14]. Only three CVEs are from 2024 or 2025 [6][13].
Attribution to a single cluster rests on infrastructure discipline that is not especially disciplined: every payload callback pointed at the same loader URL, 91.92.40[.]118/wget.sh [7]. Lin assessed the botnet has been targeting internet-facing devices across diverse regions since July 2026 [8].
Around the borrowed Mirai core, the developers have added encrypted command-and-control with a 28-command remote administration interface, an SSH brute-force scanner, a credential sniffer, and string obfuscation layered across AES-256-CTR, ChaCha20 and XOR-based key derivation [9]. Lin wrote that these capabilities "place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware" and singled out the SOCKS relay as "arguably the most operationally significant," because it lets the attacker conceal origin, pivot into internal networks and run follow-on operations through the victim's own infrastructure [4][10].
Note what that quote does and does not say. Lin describes proxying as operational tradecraft, not as a product; the report documents no marketplace, no pricing, and no customers [4][18]. The economics are still legible without them. A compromised router is worth more as a clean-looking egress point than as another packet cannoneer, and the technical bar for acquiring one is a 2016 NETGEAR RCE [4][5]. Mirai's original business was flooding Minecraft servers and selling protection from the floods, and its code went public on Hack Forums in September 2016 to muddy an investigation that eventually named Paras Jha, Josiah White and Dalton Norman [11][12]. Nine years on, its descendants are competing on infrastructure quality instead [9][12][16].
What to watch: whether the single loader IP survives contact with blocklists, because the whole cluster is currently observable through it [7]. Watch the RTU exposure specifically, since ME-RTU devices sitting behind a 2019 command injection are unlikely to be on a monthly patch cadence [5]. And watch for the resale evidence that would confirm the proxy-monetisation reading, because the published report does not carry it, nor does it state patch availability, device counts, victim numbers, or the publication year of the 13 August analysis [18].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices.
- [2]
Yi Ping (Cara) Lin, a Taiwan-based security researcher at Fortinet's FortiGuard Labs, shared an analysis of the new botnet family on August 13, calling it 'Evooo1Bot' after the hardcoded string 'evooo1' found in every binary.
ReportedView cited source - [3]
Evooo1Bot reuses the distributed denial-of-service engine from the Mirai source code.
ReportedView cited source - [4]
Lin highlighted that the SOCKS relay module is "arguably the most operationally significant" capability, as it transforms a compromised edge device into a persistent proxy, allowing the attacker to conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.
- [5]
The pre-2023 vulnerabilities observed being exploited were: CVE-2007-3010 (Alcatel OmniPCX Enterprise RCE), CVE-2016-6277 (NETGEAR multiple routers RCE), CVE-2018-14558 (Tenda AC7/AC9/AC10 command injection), CVE-2019-14931 (Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU remote command injection), CVE-2020-10987 (Tenda AC1900 Router AC15 RCE), CVE-2021-46422 (Telesquare SDT-CW3B1 command injection) and CVE-2022-37055 (D-Link routers buffer overflow).
ReportedView cited source - [6]
The post-2023 vulnerabilities observed being exploited were: CVE-2024-29269 (Telesquare TLR-2005KSH command injection), CVE-2025-10123 (D-Link DIR-823X command injection) and CVE-2025-55583 (D-Link DIR-868L B1 command injection).
ReportedView cited source
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.



