New Evooo1Bot variant enhances Mirai botnet with stealth and advanced capabilities

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Researchers at FortiGuard Labs have identified a new variant of the Mirai botnet, named Evooo1Bot, which has been actively exploiting vulnerabilities in internet-facing hardware for at least a month. This Linux-based malware targets devices from manufacturers such as Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare. The malware appears to be previously undocumented and takes advantage of unpatched bugs in these devices to spread and execute malicious activities.

According to the report, while the exact number of compromised devices worldwide remains unspecified, telemetry data indicates significant activity in regions including North America, South America, Europe, India, China, and Japan. Evooo1Bot extends beyond the typical distributed denial-of-service (DDoS) capabilities associated with Mirai, incorporating features such as encrypted communications with command-and-control servers, a scanner that identifies Secure Shell (SSH) code while avoiding devices set up as honeypots, and a “sniffer” that detects default access credentials that have not been altered since the devices were deployed.

FortiGuard Labs noted that these enhancements position Evooo1Bot as a more advanced threat compared to conventional Mirai-derived malware. Notably, the malware exploits the SOCKS protocol, allowing compromised devices to function as persistent proxies. This capability enables attackers to obscure their true origin, infiltrate internal networks, and conduct further operations through the victim’s infrastructure. The source code for Mirai was made public in 2016, leading to the emergence of various variants that have attracted the attention of law enforcement and cybersecurity experts.

For further details, refer to the full report by The Record.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

North Korean hackers steal over $10.5 million in cryptocurrency through ‘WaterPlum’ campaign targeting job seekers across 100 countries

North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as "WaterPlum," which targets job seekers across more than...

UAE Cyber Security Council and Fortinet Launch Internship Program for Emirati Students

The UAE Cyber Security Council (CSC) has partnered with Fortinet to launch a new cybersecurity internship programme aimed at equipping Emirati university students with...

AWS AgentCore Harness Vulnerability Allows Credential Exfiltration via Prompt Injection

Recent research from Unit 42 has uncovered a significant vulnerability in Amazon Web Services (AWS) AgentCore Harness, which could allow attackers to exfiltrate plaintext...

Germany’s F127 frigate program faces scrutiny over U.S. technology reliance

Germany's F127 frigate program faces scrutiny over U.S. technology reliance The German Navy's future F127 class air defense frigates are set to be equipped with...