Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Posted on August 17, 2026 By CWS

Cybersecurity experts have raised concerns over a new Linux botnet family named Evooo1Bot, which leverages the Mirai botnet’s source code to transform internet-connected devices into SOCKS5 proxies. This botnet utilizes known security flaws to infiltrate devices and extend its functionalities.

Key Features of Evooo1Bot

Evooo1Bot has been active since July 2026, according to Fortinet FortiGuard Labs. It repurposes the DDoS engine from Mirai and enhances it with additional features such as encrypted command-and-control (C2) communications, an SSH brute-force scanner, and a credential sniffer. These capabilities allow the botnet to exploit multiple vulnerabilities in devices that are publicly accessible.

The botnet targets a variety of security flaws including CVE-2007-3010, CVE-2016-6277, and CVE-2018-14558, among others. These vulnerabilities span across various routers and devices from companies like Alcatel, NETGEAR, and Tenda, posing a broad threat spectrum.

Infiltration and Operations

Once a device is compromised, the botnet executes a shell script from an external server, which downloads the appropriate binary compatible with the device’s architecture. To maintain stealth, the script deletes Bash history to remove any attack traces. The bot then establishes encrypted communications over port 443, mimicking standard HTTPS traffic to avoid detection.

After establishing a connection with its C2 server, Evooo1Bot executes various commands, including persistence installation, binary updates, and file transfers. The botnet can also intercept HTTP headers, run an SSH brute-force scanner, and initiate DDoS attacks through DNS, TCP, and UDP protocols.

Implications of Proxy Capabilities

The botnet’s ability to convert infected devices into SOCKS5 proxies adds significant value to attackers. This functionality allows attackers to mask malicious activities, circumvent geographic restrictions, and access internal networks through compromised devices. Fortinet highlights that this capability can also facilitate the creation of a distributed proxy network for anonymous traffic forwarding.

By transforming edge devices into part of a proxy infrastructure, Evooo1Bot poses a substantial threat, enhancing the attacker’s ability to conduct further operations undetected. This development underscores the need for robust cybersecurity measures to protect vulnerable devices from exploitation.

As the threat landscape evolves, staying informed about emerging threats like Evooo1Bot is crucial for maintaining cybersecurity defenses. Organizations are urged to patch known vulnerabilities and implement comprehensive security strategies to safeguard their networks.

The Hacker News Tags:command injection, CVE exploits, Cybersecurity, DDoS attacks, device vulnerabilities, Evooo1Bot, Fortinet, Linux botnet, Malware, network security, proxy infrastructure, remote code execution, SOCKS5 proxy, SSH brute-force

Post navigation

Previous Post: CoolClient Backdoor Enhanced with Rootkit for Stealth
Next Post: Hackers Target SAP Cloud Vulnerability Days After Reveal

Related Posts

Joomla JCE Vulnerability Exploited for PHP Code Execution Joomla JCE Vulnerability Exploited for PHP Code Execution The Hacker News
Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access The Hacker News
Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed Crypto-Mining Risks in Fortune 500 Cloud Systems Revealed The Hacker News
Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero The Hacker News
SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw The Hacker News
Cybersecurity Threats: SMS Blaster, OpenEMR, and Roblox Hacks Cybersecurity Threats: SMS Blaster, OpenEMR, and Roblox Hacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Businesses Unprepared for AI and Quantum Security Risks
  • WordPress Backdoor Resists Removal with Reinfection Methods
  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key
  • CISA Identifies Critical Flaw in Cisco SD-WAN Manager

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Businesses Unprepared for AI and Quantum Security Risks
  • WordPress Backdoor Resists Removal with Reinfection Methods
  • WordPress Malware Resurfaces with Self-Healing Backdoor
  • AI Impacts Cyber Attack Speed, Fundamentals Remain Key
  • CISA Identifies Critical Flaw in Cisco SD-WAN Manager

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark