New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Brief
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services.
Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai ‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top.
“FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot . The name derives from the hardcoded string “evooo1” found in every binary.” reads the report published by Fortinet.
