2026-08-16NOTABLEA new Mirai-derived botnet carries enterprise exploits and a SOCKS5 relay, turning what it lands on into pivot infrastructure
Evooo1Bot
tool · tool:evooo1bot single-source
Mirai-derived modular Linux botnet documented by FortiGuard Labs on 2026-08-13 and active since at least July 2026, named after a hardcoded string present in every sample. It reuses the leaked Mirai denial-of-service engine and adds encrypted command-and-control over TCP/443, an SSH brute-force scanner with a 150-entry dictionary carrying enterprise service-account names and two-stage honeypot detection, a SOCKS5 relay in both direct and reverse modes, an HTTP credential sniffer that reads the kernel TCP connection table for Basic-Auth and cookie headers, and an exploit module that reaches Atlassian Confluence, WSO2 products and the Kubernetes ingress-nginx admission controller alongside the usual consumer router, camera and OT-gateway targets (FortiGuard Labs, 2026-08-13).
Coverage
1
first 2026-08-16 → last 2026-08-16
Latest activity
2026-08-16
A new Mirai-derived botnet carries enterprise exploits and a SOCKS5 relay, turning what it lands on into…
Peak priority
notable
1 notable
Targets
technology
sectors: technology, telco, public-sector · regions: europe
Sources cited
3
3 hosts
Action items (1)
Do-now tasks recorded on the entries about Evooo1Bot, newest first. Check the date before acting on an older one.
- Check whether any internet-facing Atlassian Confluence, WSO2 product or Kubernetes ingress-nginx admission controller in the estate is still on a version vulnerable to CVE-2022-26134, CVE-2022-29464 or CVE-2025-1974; these are now in a commodity botnet's automated scanning arsenal rather than only a targeted-actor concern, so an instance that survived on obscurity no longer does.2026-08-16A new Mirai-derived botnet carries enterprise…
Defender insights
What each entry about Evooo1Bot tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (13 across 10 tactics)
13 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentCompromise Infrastructure: Botnet
- Initial AccessExploit Public-Facing Application
- ExecutionScheduled Task/Job: Cron
- PersistenceBoot or Logon Initialization Scripts: RC Scripts · Scheduled Task/Job: Cron · Create or Modify System Process: Systemd Service · Event Triggered Execution: Unix Shell Configuration Modification
- Privilege EscalationBoot or Logon Initialization Scripts: RC Scripts · Scheduled Task/Job: Cron · Create or Modify System Process: Systemd Service · Event Triggered Execution: Unix Shell Configuration Modification
- StealthObfuscated Files or Information · Virtualization/Sandbox Evasion: System Checks
- Credential AccessNetwork Sniffing · Brute Force: Password Guessing
- DiscoveryNetwork Sniffing · Virtualization/Sandbox Evasion: System Checks
- Command and ControlProxy: External Proxy · Encrypted Channel
- ImpactNetwork Denial of Service
Resource Development TA0042
T1584.005Compromise Infrastructure: Botnet×1
Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Execution TA0002
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Persistence TA0003
T1037.004Boot or Logon Initialization Scripts: RC Scripts×1
Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1546.004Event Triggered Execution: Unix Shell Configuration Modification×1
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (<code>/etc</code>) and the user’s home directory (<code>~/</code>) to configure the environment. All login shells on a system use /etc/profile when initiated. These configuration scripts run at the permission level of their directory and are often used to set environment variables, create aliases, and customize the user’s environment. When the shell exits or terminates, additional shell scripts are executed to ensure the shell exits appropriately.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Privilege Escalation TA0004
T1037.004Boot or Logon Initialization Scripts: RC Scripts×1
Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1546.004Event Triggered Execution: Unix Shell Configuration Modification×1
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (<code>/etc</code>) and the user’s home directory (<code>~/</code>) to configure the environment. All login shells on a system use /etc/profile when initiated. These configuration scripts run at the permission level of their directory and are often used to set environment variables, create aliases, and customize the user’s environment. When the shell exits or terminates, additional shell scripts are executed to ensure the shell exits appropriately.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×1
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Credential Access TA0006
T1040Network Sniffing×1
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1110.001Brute Force: Password Guessing×1
Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Password guessing may or may not take into account the target's policies on password complexity or use policies that may lock accounts out after a number of failed attempts.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Discovery TA0007
T1040Network Sniffing×1
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Command and Control TA0011
T1090.002Proxy: External Proxy×1
Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
T1573Encrypted Channel×1
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Impact TA0040
T1498Network Denial of Service×1
Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Evidence: 2026-08-16/evooo1bot-mirai-derivative-enterprise-exploits-socks5-relay · ATT&CK page ↗
Entries about Evooo1Bot (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Alcatel-Lucent OmniPCX Enterprise Communication Server×1
- Atlassian Confluence×1
- D-Link DIR-823X×1
- Hikvision IP cameras×1
- Kubernetes ingress-nginx Controller×1
- Mitsubishi Electric ME-RTU×1
- NETGEAR routers×1
- Tenda AC10×1
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- fortinet.com1 (33%)
- therecord.media1 (33%)
All cited sources (3)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/
- fortinet.comFortiGuard Labs (Fortinet)https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code