A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.
Created: 2026-08-17
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。