Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying.

Evooo1Bot is the threat that reaches internet-facing edge systems by exploiting known flaws and attempting weak SSH logins.

Its operators can then issue commands through an encrypted control channel. The campaign is more than another basic denial-of-service operation.

It combines code drawn from the leaked Mirai framework with proxy, credential-sniffing, file-transfer, and exploit functions.

That mix gives intruders several ways to use a single compromised device and mirrors recent Mirai botnet trends toward broader abuse.

Fortinet analysts identified the malware after seeing active exploitation attempts against a range of edge devices.

Fortinet said in a report shared with Cyber Security News (CSN) that telemetry showed the botnet targeting internet-facing devices from July 2026, with campaigns tracked separately by the weakness used.

The immediate danger is not limited to a device going offline. An infected system can be enlisted in attacks against others, used to hide an operator’s connection, or serve as a stepping stone toward internal resources.

Payload in exploit pcap (Source – Fortinet)

The threat therefore adds weight to edge device defense lessons for organizations that leave appliances exposed and unpatched.

Sixteen DDoS Methods Expand the Threat

Evooo1Bot carries 16 traffic-flooding methods, including UDP, DNS, SYN, GRE, and fragmented TCP attacks.

The engine is structurally consistent with leaked Mirai code, but its HTTP flood function can accept operator-selected request methods, headers, and expected values. That flexibility can make malicious traffic look less uniform during an attack.

The bot also contains an exploit dispatcher that can deliver payloads through known weaknesses in products from vendors including D-Link, Tenda, Hikvision, Zyxel, TP-Link, and others.

Some entries do not work as implemented, but the list still helps operators test many targets. It also reinforces why network device patching practices remain central to limiting botnet growth.

Following compromise, a loader retrieves the binary suited to the victim’s processor, runs it temporarily, then clears Bash history.

The malware can establish persistence through system services, startup scripts, scheduled tasks, shell profiles, and rc.local.

wget.sh (Source – Fortinet)

It also checks for analysis tools, sandboxes, virtual machines, and containers before connecting to its command server on port 443.

For defenders, the concern is scale. Each infected appliance can add attack capacity and fresh access points.

Prompt firmware updates, removal of unnecessary public exposure, strong unique administrative credentials, and monitoring of unusual outbound connections are the basic steps that reduce that opportunity.

SOCKS5 Proxies Turn Victims Into Relays

The SOCKS relay module makes Evooo1Bot especially useful beyond denial-of-service attacks. In direct mode, it can open a SOCKS5 listener, normally on TCP port 1080.

In reverse mode, the bot creates encrypted outbound links to an operator-selected relay server, allowing traffic to pass through the victim without exposing a listener to the internet.

That design can conceal the real source of malicious activity, help bypass location-based controls, and provide a route into networks behind a compromised device.

Similar SOCKS5 proxy abuse tactics show why defenders should treat unexplained proxy behavior as an intrusion signal rather than a minor network anomaly.

Evooo1Bot also includes an SSH scanner with more than 150 embedded credentials, including service-account names used in business environments.

XOR-encoded string (Source – Fortinet)

It tries to avoid honeypots by checking SSH banners and probing a successful target for signs of emulation. A separate sniffer can collect HTTP Basic Authorization and Cookie headers, raising the potential cost of an infection.

Organizations should inventory internet-exposed equipment, apply vendor fixes quickly, disable remote management where it is not needed, and review outbound encrypted sessions from appliances that rarely initiate them.

Network teams should also investigate new SOCKS listeners, unexpected scheduled downloads, and systems contacting the listed infrastructure. They cannot remove an existing compromise alone, but they help teams find and contain it early.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP address 91.92.40[.]118 Command-and-control infrastructure and loader host observed in the campaign
URL http://91.92.40[.]118/wget.sh Loader URL used in payload callbacks
File name wget.sh Loader script that downloads and executes architecture-matched binaries
SHA-256 f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109 Evooo1Bot sample hash
SHA-256 4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d Evooo1Bot sample hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world