← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 17, 2026 · 05:25via CyberPress

Evooo1Bot Linux Botnet Hijacks Routers and Firewalls for DDoS, SOCKS5 Proxy and Credential Theft

Brief

The threat targets internet-facing routers, firewalls, cameras, and other edge devices, turning compromised systems into tools for DDoS attacks, SOCKS5 proxy relays , credential theft, and further network intrusion.

Evooo1Bot borrows its DDoS engine from the leaked Mirai source code but adds a broader set of functions.

These include encrypted command-and-control (C2) communication, SSH brute-force scanning, traffic sniffing, remote shell access, file transfers, persistence, and an exploit module that targets known vulnerabilities.

FortiGuard telemetry shows the campaign has been active since July 2026. Researchers observed exploit attempts that downloaded payloads from 91.

  • 40[. ]118/wget. sh .

The script detects a target device’s CPU architecture, downloads the matching Linux binary, grants execution permission, and runs it.

Read more on CyberPress