Skip to content

Build1 publisher3 min readPublished

One Mirai variant now proxies, sniffs and spreads: the appliance layer is a pivot, not DDoS fodder

FortiGuard Labs says Evooo1Bot packs SOCKS5 relaying, credential sniffing, SSH spreading and 16 flood modes into one binary across 12 CPU architectures. The tunnel matters more than the flood.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • FortiGuard Labs published a report titled Multi-Functional Linux Botnet 'Evooo1Bot', severity High, with release date listed as 2026-08-13; the malware is identified as Evooo1Bot, a Mirai variant.
  • Evooo1Bot breaks into Linux gateways using known vulnerabilities and over 150 credential combinations, trying more than 150 username and password combinations on SSH.
  • The loader deploys payloads that support 12 CPU architectures and chooses the correct payload from 12 binary options matching the CPU architecture.
  • It combines encrypted C2 communications, SOCKS5 relaying, credential sniffing, SSH spreading, persistence, and 16 types of DDoS attacks into a single package.
  • CVEs listed include CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583, and others.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

FortiGuard Labs has documented a Mirai-variant Linux botnet it calls Evooo1Bot, rated High severity, that combines encrypted command-and-control, SOCKS5 relaying, credential sniffing, SSH spreading, persistence and 16 types of DDoS attack in a single package [1][4]. The consequence is not another flood source: it is that the router, camera and gateway layer most teams never patch now ships with a proxy, a sniffer and a scanner attached.

Entry is unglamorous. According to the FortiGuard write-up, the botnet breaks into Linux gateways using known vulnerabilities plus more than 150 username and password combinations, and no user action is required because the attack begins as an HTTP request to a public management interface or an SSH login attempt [2][25]. The listed CVEs run from CVE-2007-3010 to CVE-2025-55583 [5], an exploit set spanning roughly 18 years of unpatched estate [1]. The affected product list is not only consumer hardware: alongside NETGEAR, Tenda and D-Link routers, Hikvision cameras, Zyxel firewalls, TP-Link Archer AX21, Alcatel OmniPCX Enterprise, Mitsubishi Electric ME-RTU and Telesquare devices, it includes Atlassian Confluence, Kubernetes ingress-nginx, PHP-CGI and WSO2 products [6].

Once an exploit lands, the loader is pulled from 91.92.40[.]118/wget.sh with a campaign label identifying the target, trying wget, then busybox wget, then curl, then tftp [7][8]. It picks one of 12 architecture-specific binaries, writes it to a temporary path, sets execute permissions and runs it, then clears Bash history [9][3][10]. The binary decrypts more than 60 string blocks using AES, ChaCha20 and XOR, then fingerprints filesystem, processes, services and VM or container markers for sandboxes and honeypots before dialling an encrypted C2 over TCP 443 [11][12][13]. Its SSH scanner checks banners against known honeypot strings, and after a successful login checks /proc/version, the PID 1 command line and Cowrie or Kippo paths before delivering the payload [15][16].

The pivot capability is the part that changes triage. Direct mode opens a TCP 1080 listener on the victim; reverse mode makes an outbound encrypted relay connection, and multiple proxy sessions run independently so the victim IP can be used for attack relaying or internal network access [18][19]. The sniffer module harvests HTTP Basic Authorization and Cookie headers into /tmp/.sniff.log [20]. On an appliance that terminates internal traffic, that is credentials plus a tunnel on the same box. The exploit module then scans for further devices and enterprise applications and delivers the same loader [22], and the DDoS side runs 16 flood methods inherited from Mirai [21].

Two caveats worth holding. The !persist command tries systemd, SysV init, cron, shell profiles and rc.local at once [17], but FortiGuard's own inference is that writing to those paths needs high privileges, so success depends on the service privileges and device configuration at the time of breach [23]. Public reports do not describe any privilege escalation built into Evooo1Bot [24], and no group is named [29].

Watch for requests to known vulnerability paths, loader downloads, unknown ELF files, cleared Bash history and continuous TCP 443 traffic pre-infection [26]; afterwards, a TCP 1080 listener, outbound relay connections, many short SSH connections, proxy traffic pointing inward, and DDoS egress [27]. The indicator list also names a masquerading systemd unit, though the source text is cut off mid-string at "Apache HTTPD Cach" [28]. Egress filtering from the appliance VLAN is the cheap control here, since a reverse relay only works if the device can call out.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories