Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks

Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks

Posted on August 17, 2026 By CWS

The Evooo1Bot botnet, a newly detected threat, is targeting edge devices connected to the internet, exploiting known vulnerabilities and weak SSH credentials to gain access. Once compromised, these devices can be used for various malicious activities, including traffic relaying and remote access.

Methods of Exploitation

Evooo1Bot attacks internet-facing systems by leveraging known security flaws and attempting to breach weak SSH logins. Upon successful infiltration, commands can be issued through an encrypted control channel, enabling a wide range of operations beyond simple denial-of-service attacks.

The botnet integrates elements from the leaked Mirai framework, alongside capabilities like proxy, credential sniffing, file transfer, and exploitation. This combination allows attackers to maximize the utility of a single compromised device, reflecting recent trends in Mirai botnet operations.

Diverse DDoS Techniques

Fortinet researchers identified the malware through active exploitation attempts on various edge devices. Their report, shared with Cyber Security News, indicates that the botnet has been targeting internet-exposed devices since July 2026. The campaigns are categorized based on the vulnerabilities exploited.

Evooo1Bot employs 16 distinct DDoS methods, including UDP, DNS, SYN, GRE, and fragmented TCP attacks. Its structure is consistent with leaked Mirai code, but it offers enhanced flexibility in its HTTP flood function, allowing for customized request methods and headers, making malicious traffic less uniform.

SOCKS5 Proxy Capabilities

A notable feature of Evooo1Bot is its SOCKS relay module, which extends its functionality beyond DDoS attacks. The bot can establish a SOCKS5 listener on TCP port 1080 or create encrypted outbound connections to a relay server, effectively concealing the origin of malicious activities.

The botnet includes an SSH scanner with over 150 embedded credentials, which it uses to avoid honeypots by inspecting SSH banners and testing targets for signs of emulation. Additionally, a sniffer feature captures HTTP Basic Authorization and Cookie headers, increasing the potential damage of an infection.

Implications and Protective Measures

The immediate risk of Evooo1Bot is not just device downtime. An infected system can participate in further attacks, disguise an attacker’s presence, or provide a pathway into internal networks. Organizations are advised to review their internet-exposed equipment, apply vendor updates promptly, and disable unnecessary remote management features.

To mitigate risks, network teams should monitor for new SOCKS listeners, unexpected downloads, and outbound encrypted sessions from devices that rarely initiate them. While detecting an existing compromise is challenging, early identification and containment are crucial.

In conclusion, Evooo1Bot underscores the importance of robust edge device security measures. Regular firmware updates, strong administrative credentials, and vigilance against unusual network behaviors are essential to defend against such sophisticated botnets.

Cyber Security News Tags:cyber threats, Cybersecurity, DDoS attacks, edge devices, Evooo1Bot, Fortinet, IoT security, Linux botnet, Malware, Mirai framework, network defense, network security, SOCKS5 proxy, SSH vulnerability

Post navigation

Previous Post: Web3 Job Scam Delivers NeedleStealer and hVNC RAT
Next Post: macOS Screen Sharing Flaw Exploited for Cryptomining

Related Posts

Hackers Exploit Microsoft Tools to Target HR and Payroll Hackers Exploit Microsoft Tools to Target HR and Payroll Cyber Security News
Threat Actors Breaking to Enterprise Infrastructure Within 18 Minutes From Initial Access Threat Actors Breaking to Enterprise Infrastructure Within 18 Minutes From Initial Access Cyber Security News
Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads Hackers Attacking macOS Users With Spoofed Homebrew Websites to Inject Malicious Payloads Cyber Security News
Critical Microsoft 365 Copilot Flaws Resolved by Microsoft Critical Microsoft 365 Copilot Flaws Resolved by Microsoft Cyber Security News
Critical CosmosEscape Flaw in Azure Cosmos DB Uncovered Critical CosmosEscape Flaw in Azure Cosmos DB Uncovered Cyber Security News
BMC Firmware Vulnerabilities Allow Attackers to Bypass Signature Verification Features BMC Firmware Vulnerabilities Allow Attackers to Bypass Signature Verification Features Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Z.ai Launches GLM-5.3 with Enhanced Coding and Security
  • macOS Screen Sharing Flaw Exploited for Cryptomining
  • Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks
  • Web3 Job Scam Delivers NeedleStealer and hVNC RAT
  • Data Breach Hits Fortune 500 Firms via Azure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Z.ai Launches GLM-5.3 with Enhanced Coding and Security
  • macOS Screen Sharing Flaw Exploited for Cryptomining
  • Evooo1Bot Botnet Exploits Edge Devices with DDoS Attacks
  • Web3 Job Scam Delivers NeedleStealer and hVNC RAT
  • Data Breach Hits Fortune 500 Firms via Azure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark