Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Posted on August 17, 2026 By CWS

Cybersecurity experts have raised concerns over a new Linux botnet family named Evooo1Bot, which leverages the Mirai botnet’s source code to transform internet-connected devices into SOCKS5 proxies. This botnet utilizes known security flaws to infiltrate devices and extend its functionalities.

Key Features of Evooo1Bot

Evooo1Bot has been active since July 2026, according to Fortinet FortiGuard Labs. It repurposes the DDoS engine from Mirai and enhances it with additional features such as encrypted command-and-control (C2) communications, an SSH brute-force scanner, and a credential sniffer. These capabilities allow the botnet to exploit multiple vulnerabilities in devices that are publicly accessible.

The botnet targets a variety of security flaws including CVE-2007-3010, CVE-2016-6277, and CVE-2018-14558, among others. These vulnerabilities span across various routers and devices from companies like Alcatel, NETGEAR, and Tenda, posing a broad threat spectrum.

Infiltration and Operations

Once a device is compromised, the botnet executes a shell script from an external server, which downloads the appropriate binary compatible with the device’s architecture. To maintain stealth, the script deletes Bash history to remove any attack traces. The bot then establishes encrypted communications over port 443, mimicking standard HTTPS traffic to avoid detection.

After establishing a connection with its C2 server, Evooo1Bot executes various commands, including persistence installation, binary updates, and file transfers. The botnet can also intercept HTTP headers, run an SSH brute-force scanner, and initiate DDoS attacks through DNS, TCP, and UDP protocols.

Implications of Proxy Capabilities

The botnet’s ability to convert infected devices into SOCKS5 proxies adds significant value to attackers. This functionality allows attackers to mask malicious activities, circumvent geographic restrictions, and access internal networks through compromised devices. Fortinet highlights that this capability can also facilitate the creation of a distributed proxy network for anonymous traffic forwarding.

By transforming edge devices into part of a proxy infrastructure, Evooo1Bot poses a substantial threat, enhancing the attacker’s ability to conduct further operations undetected. This development underscores the need for robust cybersecurity measures to protect vulnerable devices from exploitation.

As the threat landscape evolves, staying informed about emerging threats like Evooo1Bot is crucial for maintaining cybersecurity defenses. Organizations are urged to patch known vulnerabilities and implement comprehensive security strategies to safeguard their networks.

The Hacker News Tags:command injection, CVE exploits, Cybersecurity, DDoS attacks, device vulnerabilities, Evooo1Bot, Fortinet, Linux botnet, Malware, network security, proxy infrastructure, remote code execution, SOCKS5 proxy, SSH brute-force

Post navigation

Previous Post: CoolClient Backdoor Enhanced with Rootkit for Stealth
Next Post: Hackers Target SAP Cloud Vulnerability Days After Reveal

Related Posts

Iranian Hackers Target U.S. Networks with New Malware Iranian Hackers Target U.S. Networks with New Malware The Hacker News
Secure AI-Driven Development: Webinar Insights Secure AI-Driven Development: Webinar Insights The Hacker News
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines The Hacker News
Chinese APT Group Deploys TinyRCT in Southeast Asia Chinese APT Group Deploys TinyRCT in Southeast Asia The Hacker News
Weekly Cybersecurity Recap: ShareFile Threat and More Weekly Cybersecurity Recap: ShareFile Threat and More The Hacker News
Smart TV Proxyware and AI in Cybercrime: Key Updates Smart TV Proxyware and AI in Cybercrime: Key Updates The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Deploy Malware Amid Conflicting Goals
  • Chinese APT Exploits VMware Flaw for Ransomware Attack
  • MessiahGPT AI Model Threatens Security with Cybercrime Tools
  • Hackers Target SAP Cloud Vulnerability Days After Reveal
  • Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Deploy Malware Amid Conflicting Goals
  • Chinese APT Exploits VMware Flaw for Ransomware Attack
  • MessiahGPT AI Model Threatens Security with Cybercrime Tools
  • Hackers Target SAP Cloud Vulnerability Days After Reveal
  • Evooo1Bot Linux Botnet Exploits Edge Device Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark