← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 07:18via Security Affairs

New Mirai-Based Evooo1Bot Botnet Targets Linux Devices

Brief

Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services.

Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai ‘s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a credential sniffer, and a SOCKS5 proxy module on top.

“FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot . The name derives from the hardcoded string “evooo1” found in every binary.” reads the report published by Fortinet.

Read more on Security Affairs