Published Security3 min read
Mirai's Descendants Are Now Proxy Vendors, and Your Inventory Does Not List the Hardware
FortiGuard Labs says a previously undocumented botnet called Evooo1Bot is exploiting unpatched edge gear from six vendors, adding encrypted C2, honeypot avoidance and default-credential sniffing.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Researchers said Thursday that malware adding multiple capabilities to the Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month.
- Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs.
- Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said.
- Evooo1Bot appears to be previously undocumented, the researchers said.
- The report does not specify how many devices have been compromised worldwide; FortiGuard telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan.
Compiled by The WatchSomething wrong?How this is made
Why it matters
FortiGuard Labs said Thursday that a previously undocumented Linux botnet it calls Evooo1Bot has spent at least a month exploiting unpatched vulnerabilities in internet-facing hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare [1][2][3][4]. The DDoS capability is the least interesting part; the malware turns each compromised device into a proxy, which is a different business model with different consequences for whoever owns the network the device sits in [8][9].
On top of Mirai's inherited flooding functions, FortiGuard lists encrypted communications with command-and-control servers, a scanner that hunts for SSH and skips devices that are obviously set up as honeypots, and a sniffer that looks for default access credentials never changed since the device was commissioned [6]. "These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware," the researchers wrote [7]. The company's telemetry puts activity in North America, South America, Europe, India, China and Japan, and the report does not say how many devices have been taken [5].
FortiGuard calls the abuse of the SOCKS proxy protocol "arguably the most operationally significant" feature, because it lets attackers "conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure" [8][9]. That is the part that should worry anyone whose CMDB stops at servers and laptops. The six vendors named here sell the sort of small routers, industrial equipment and telecom boxes that get installed once and then drop out of patch cycles entirely [2][12]. The honeypot-skipping scanner also degrades the main instrument researchers use to size these campaigns, so external counts of this thing will run low [6][13].
Evooo1Bot is not an outlier. Mirai's source code went public in 2016, and the family has produced a decade of variants [10]. Two of them, Aisuru and KimWolf, were targeted in March by agencies from the United States, Canada and Germany, and a Canadian man was charged in May with running KimWolf [11]. That did not end it: Palo Alto Networks Unit 42 found Kimwolf v7 on February 3, 2026, with an HTTP/2 flood built on nghttp2 that mimics Chrome's header behaviour to defeat fingerprint-based mitigation [14][15]. Its command server is resolved through Ethereum Name Service using five hard-coded public blockchain RPC endpoints shuffled before each attempt, with a Tor hidden service behind that and a local proxy on 127.0.0.1:23075 behind that, which Unit 42 describes as a direct answer to two takedowns in December 2025 [16][17]. Version 7 also strips scanning and exploitation out of the main binary and hands initial access to external loaders, and consolidates 43 named attack commands into 15 numbered methods across layers 3 through 7 [18][19]. Unit 42 clustered the infrastructure across 22 IP addresses in Saint Petersburg sharing one SSH host key from December 2025 to February 2026 [20].
What to watch: whether your edge inventory can answer, today, how many Telesquare or Tenda devices you own and what firmware they run [2]. On the Kimwolf side, Unit 42's guidance is to treat Android TV boxes as untrusted and segment them, disable Android Debug Bridge or limit it to USB, and alert on outbound HTTPS to Ethereum RPC endpoints, Tor or SOCKS5 traffic from consumer media devices, connections to localhost port 23075, and any process named netd_service [21][22]. The propagation route there is residential proxy services reaching boxes that ship with ADB open on port 5555 and no authentication required [23].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Researchers said Thursday that malware adding multiple capabilities to the Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month.
- [2]
Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs.
- [3]
Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said.
- [4]
Evooo1Bot appears to be previously undocumented, the researchers said.
- [5]
The report does not specify how many devices have been compromised worldwide; FortiGuard telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan.
- [6]
Beyond Mirai's usual DDoS functions, Evooo1Bot's features include encrypted communications with command-and-control servers; a scanner that looks for SSH code and skips devices clearly set up as honeypots for malicious traffic; and a sniffer that looks for default access credentials that have not been changed since a device was put into service.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 12Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum
- therecord.mediaAug 13New Mirai variant adds stealth capabilities to notorious botnet code
Additional citations
- FortiGuard Labs, via The Record
- FortiGuard Labs
- Palo Alto Networks Unit 42, via Security Affairs
- Unit 42



