Cybersecurity researchers at Fortinet FortiGuard Labs have identified a previously undocumented Linux botnet known as Evooo1Bot that expands on the capabilities of the leaked Mirai botnet source code while introducing several advanced features for cyber operations. According to the researchers, the malware is designed to compromise internet facing devices and convert them into SOCKS5 proxy nodes that can be used by threat actors to relay malicious traffic and support additional attacks. Evidence gathered by Fortinet indicates that the botnet has been active since July 2026 and has been targeting publicly accessible devices by exploiting multiple known security vulnerabilities. While the malware retains Mirai distributed denial of service engine, it incorporates encrypted command and control communications, an SSH brute force scanner, a SOCKS relay module, a credential sniffer and an exploit framework capable of targeting a broad range of known vulnerabilities.
Fortinet reported that Evooo1Bot exploits vulnerabilities affecting a variety of enterprise and networking products, including devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D Link. Among the vulnerabilities used during attacks are CVE 2007 3010, CVE 2016 6277, CVE 2018 14558, CVE 2019 14931, CVE 2020 10987, CVE 2021 46422, CVE 2022 37055, CVE 2024 29269, CVE 2025 10123 and CVE 2025 55583. Successful exploitation downloads a loader script named wget.sh from an external server, which then retrieves the malware binary compiled for the target device processor architecture. Researchers noted that the script also deletes Bash history after execution to reduce evidence of the compromise. Once installed, the malware performs checks to detect analysis tools, sandbox environments and virtual machines before establishing encrypted communication with its command and control server over port 443. Using the HTTPS port allows the malware to blend with legitimate encrypted traffic, making detection more difficult within enterprise networks.
After registering an infected device with the command and control infrastructure, Evooo1Bot can receive a wide range of instructions from its operators. According to Fortinet, the malware supports commands to establish persistence, update or remove itself, upload and download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, perform SSH brute force scanning and execute distributed denial of service attacks using DNS, TCP and UDP protocols. The malware also includes an HTTP based exploit dispatcher capable of targeting additional vulnerabilities affecting Hikvision, Atlassian Confluence, WSO2, Zyxel, TP Link, PHP, D Link and Kubernetes products. This extensive exploit arsenal enables the botnet to expand its reach by compromising more internet connected devices while maintaining operational flexibility for different attack scenarios. Researchers noted that the malware architecture demonstrates a significant evolution from the original Mirai code base by combining exploitation, credential theft, proxy services and denial of service functionality into a single framework.
One of the most significant capabilities identified by Fortinet is the malware SOCKS5 proxy module, which transforms infected routers, firewalls, IP cameras and other edge devices into proxy servers controlled by threat actors. Researchers explained that compromised systems can then be used to disguise malicious traffic, bypass geographic restrictions or provide indirect access to internal networks through already infected devices. In larger campaigns, this functionality can also support the creation of distributed proxy infrastructure that enables anonymous traffic forwarding or commercial proxy services using compromised residential and enterprise networks. Fortinet stated that the ability to convert infected devices into proxy nodes significantly increases their operational value for attackers, allowing them to conceal malicious activity while expanding the overall effectiveness of the botnet.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





