FortiGuard Labs disclosed a previously undocumented Linux botnet, Evooo1Bot, a Mirai-derived malware family that has been actively targeting Internet-facing devices since at least July 2026. The botnet exploits known vulnerabilities in routers, firewalls, IP cameras, and other edge hardware from vendors including Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare, then deploys architecture-specific binaries from a shared loader at 91.92.40[.]118. Researchers said the malware clears bash history after infection, performs anti-analysis and anti-sandbox checks, and communicates with its command-and-control infrastructure over encrypted channels on port 443.
Evooo1Bot expands on typical Mirai behavior with SSH brute-force scanning, credential sniffing for default or exposed access credentials, persistence mechanisms, and an integrated exploit module for multiple known flaws. Researchers highlighted its reverse SOCKS proxy capability as the most consequential feature because compromised edge devices can be repurposed as long-lived relay nodes to conceal attacker origin, support lateral movement, and enable follow-on intrusions into internal networks. Reported activity has been concentrated across North America, South America, Europe, India, China, and Japan, underscoring broad exposure for organizations running unpatched perimeter devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs said telemetry from Evooo1Bot command-and-control infrastructure showed the botnet had been actively targeting Internet-facing devices since July 2026. The activity involved exploitation attempts against multiple known vulnerabilities with payload callbacks to a common loader URL.
The Mirai botnet source code was publicly released in 2016, enabling numerous later malware variants. Evooo1Bot is described as one such Mirai-derived descendant.
FortiGuard Labs reported a previously undocumented Linux botnet family named Evooo1Bot and detailed its Mirai-derived architecture, encrypted C2, SSH brute-force scanning, SOCKS proxying, credential sniffing, persistence, and exploit modules. The report also stated FortiGuard security products detect or block the malware and associated infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcetherecord.media
Open sourcefeeds.fortinet.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.