Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Posted on August 17, 2026 By CWS

Cybersecurity experts have raised concerns over a new Linux botnet family named Evooo1Bot, which leverages the Mirai botnet’s source code to transform internet-connected devices into SOCKS5 proxies. This botnet utilizes known security flaws to infiltrate devices and extend its functionalities.

Key Features of Evooo1Bot

Evooo1Bot has been active since July 2026, according to Fortinet FortiGuard Labs. It repurposes the DDoS engine from Mirai and enhances it with additional features such as encrypted command-and-control (C2) communications, an SSH brute-force scanner, and a credential sniffer. These capabilities allow the botnet to exploit multiple vulnerabilities in devices that are publicly accessible.

The botnet targets a variety of security flaws including CVE-2007-3010, CVE-2016-6277, and CVE-2018-14558, among others. These vulnerabilities span across various routers and devices from companies like Alcatel, NETGEAR, and Tenda, posing a broad threat spectrum.

Infiltration and Operations

Once a device is compromised, the botnet executes a shell script from an external server, which downloads the appropriate binary compatible with the device’s architecture. To maintain stealth, the script deletes Bash history to remove any attack traces. The bot then establishes encrypted communications over port 443, mimicking standard HTTPS traffic to avoid detection.

After establishing a connection with its C2 server, Evooo1Bot executes various commands, including persistence installation, binary updates, and file transfers. The botnet can also intercept HTTP headers, run an SSH brute-force scanner, and initiate DDoS attacks through DNS, TCP, and UDP protocols.

Implications of Proxy Capabilities

The botnet’s ability to convert infected devices into SOCKS5 proxies adds significant value to attackers. This functionality allows attackers to mask malicious activities, circumvent geographic restrictions, and access internal networks through compromised devices. Fortinet highlights that this capability can also facilitate the creation of a distributed proxy network for anonymous traffic forwarding.

By transforming edge devices into part of a proxy infrastructure, Evooo1Bot poses a substantial threat, enhancing the attacker’s ability to conduct further operations undetected. This development underscores the need for robust cybersecurity measures to protect vulnerable devices from exploitation.

As the threat landscape evolves, staying informed about emerging threats like Evooo1Bot is crucial for maintaining cybersecurity defenses. Organizations are urged to patch known vulnerabilities and implement comprehensive security strategies to safeguard their networks.

The Hacker News Tags:command injection, CVE exploits, Cybersecurity, DDoS attacks, device vulnerabilities, Evooo1Bot, Fortinet, Linux botnet, Malware, network security, proxy infrastructure, remote code execution, SOCKS5 proxy, SSH brute-force

Post navigation

Previous Post: CoolClient Backdoor Enhanced with Rootkit for Stealth
Next Post: Hackers Target SAP Cloud Vulnerability Days After Reveal

Related Posts

North Korean Group Linked to Axios npm Attack North Korean Group Linked to Axios npm Attack The Hacker News
New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands The Hacker News
Addressing the Hidden Costs of Credential Incidents Addressing the Hidden Costs of Credential Incidents The Hacker News
Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails The Hacker News
SkillCloak Evades AI Scanners with New Techniques SkillCloak Evades AI Scanners with New Techniques The Hacker News
A Pragmatic Approach To NHI Inventories  A Pragmatic Approach To NHI Inventories  The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Models Mistakenly Target Real Company Due to Naming Error
  • Enhancing MCP Server Security to Protect Enterprise Secrets
  • ChainDrop Worm Compromises npm Packages via GitHub
  • AI Agents Deploy Malware Amid Conflicting Goals
  • Chinese APT Exploits VMware Flaw for Ransomware Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Models Mistakenly Target Real Company Due to Naming Error
  • Enhancing MCP Server Security to Protect Enterprise Secrets
  • ChainDrop Worm Compromises npm Packages via GitHub
  • AI Agents Deploy Malware Amid Conflicting Goals
  • Chinese APT Exploits VMware Flaw for Ransomware Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark