INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Linux Botnet Exploits Known Flaws to Turn Victims Into Proxies

| 2026-08-17 09:29 HIGH HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
The Evooo1Bot Linux botnet, a variant of the Mirai DDoS engine, has been targeting Internet-facing devices since at least July. This sophisticated malware exploits vulnerabilities as old as 2007 and recent flaws discovered last year, giving attackers a multifunctional platform for compromising and monetizing vulnerable Linux-based devices. The botnet's entry points include command injection and remote code execution bugs such as CVE-2007-3010 to CVE-2020-10987. With its reverse SOCKS relay module being the most significant advancement, Evooo1Bot can turn compromised edge devices into full attacker infrastructure, hiding their real location and providing a foothold for deeper network infiltration. This highlights how Mirai's leaked codebase continues to be a gift that keeps on giving for attackers, allowing them to evolve from relative novelties to sophisticated threats.
Technical Mitigations AI-generated
* Implement and regularly update software updates for Internet-facing devices to ensure they have the latest security patches, especially those related to known vulnerabilities such as CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, and CVE-2020-10987. * Use secure protocols for communication with Internet-facing devices, such as encrypted SSH or HTTPS, and avoid using hardcoded strings like "evooo1" that can be exploited by attackers. * Monitor device logs and system configurations to detect potential vulnerabilities or suspicious activity, and take prompt action if necessary to prevent exploitation. * Implement a robust patch management process to ensure all affected systems are patched before allowing them to connect to the internet, and consider using a vulnerability scanning tool to identify unpatched devices. * Use secure boot mechanisms for Linux-based devices to prevent attackers from installing malware or modifying system configurations without being detected.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

wg•••••.sh
se•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-10123CVE-2025-10123 CVE-2024-29269CVE-2024-29269 CVE-2022-29464CVE-2022-29464 CVE-2024-10914CVE-2024-10914 CVE-2024-4577CVE-2024-4577 CVE-2020-10987CVE-2020-10987 CVE-2019-14931CVE-2019-14931 CVE-2025-55583CVE-2025-55583 CVE-2016-6277CVE-2016-6277 CVE-2007-3010CVE-2007-3010 CVE-2025-1974CVE-2025-1974 CVE-2021-46422CVE-2021-46422 CVE-2021-36260CVE-2021-36260 CVE-2022-37055CVE-2022-37055 CVE-2022-26134CVE-2022-26134 CVE-2018-14558CVE-2018-14558 CVE-2022-30525CVE-2022-30525 CVE-2023-1389CVE-2023-1389
Target & Sectors
EUROPE EUROPE
Incident Timeline
‎September 2016
Threat actors used a publicly leaked version of Evooo1Bot to target Edge devices, exploiting known flaws in the device's software.
tactic Ddos
attribution Hack Forums
attribution FBI
‎2025/08/17
The researchers discovered the hardcoded string "evooo1" in every binary of an Evooo1Bot Linux botnet, exploiting known vulnerabilities as old as 2007.
tactic Botnet
‎July 2026
Evooo1Bot uses the Mirai botnet's distributed denial-of-service engine to launch DDoS attacks.
tactic Botnet
tactic T1584.005 - Botnet
tactic Ddos
organisation CVE-2007-3010
organisation CVE-2018-14558
organisation CVE-2022-37055
infrastructure 91.92.40
organisation Mitsubishi Electric Europe B.V. ME-RTU
organisation INEA ME-RTU
organisation Command
organisation CPU
organisation DNS
organisation TCP
organisation UDP
organisation CVE
organisation CVE-2022
organisation Zyxel
organisation PHP
organisation IP
‎August 13
Threat actors used a known flaw in the Linux operating system to exploit vulnerabilities and turn Edge devices into SOCKS5 proxies.
tactic Botnet
target_region Taiwan, Province of China
organisation Fortinet’s FortiGuard Labs
‎2026/08/14
Threat actors used the Evooo1Bot Linux Botnet to exploit known flaws in Edge devices and turn them into SOCKS5 proxies.
tactic Ddos
attribution Hack Forums
attribution FBI
‎Aug 17, 2026
Threat actors used a DDoS engine from the publicly leaked Mirai source code to exploit known vulnerabilities in Edge devices and turn them into SOCKS5 proxies.
organisation DDoS
organisation SSH
‎2026/08/17
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies.
infrastructure Linux
organisation Mirai
organisation Alcatel
organisation NETGEAR
organisation Tenda
organisation Mitsubishi Electric
organisation Telesquare
organisation CVE-2018
organisation OG' Social Engineer
organisation Fortigauard
organisation CVE-2018-14558
organisation Mitsubishi Electric Europe B.V. ME-RTU
organisation INEA ME-RTU
infrastructure 14558 Alcatel OmniPCX remote code execution
organisation DDoS
organisation IoT
organisation Smart Devices
organisation Evooo1Bot
organisation Defending Against Mirai Variants
organisation SSH
organisation AES-256-CTR
organisation XOR
organisation CVE-2022-37055
organisation CVE-2025-10123
organisation IPS
organisation TCP
organisation IP
organisation GhostJacking
organisation Secure.com
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎91.92.40
Software Version
Metrics
infrastructure
14,558
Alcatel Omnipcx Remote Code Execution
Intelligence Sources