---
schema: 1
kind: threat
title: "Evooo1Bot: a Mirai-derived Linux botnet whose exploit arsenal reaches Confluence, WSO2 and Kubernetes ingress-nginx, and whose SSH dictionary is stocked with enterprise service accounts rather than router defaults"
headline: "A new Mirai-derived botnet carries enterprise exploits and a SOCKS5 relay, turning what it lands on into pivot infrastructure"
summary: >
  FortiGuard Labs documented Evooo1Bot on 2026-08-13, a previously undocumented Mirai-derived Linux
  botnet active since at least July 2026. What separates it from the usual Mirai derivative is reach
  and purpose: alongside the expected router, camera and OT-gateway exploits, its module set carries
  working pre-authentication chains against Atlassian Confluence, WSO2 products and the Kubernetes
  ingress-nginx admission controller, its SSH brute-forcer cycles enterprise service-account names
  rather than IoT defaults, and it ships a SOCKS5 relay and an HTTP credential sniffer — so a
  compromised host becomes pivot and interception infrastructure, not just a DDoS node.
discovered_at: "2026-08-16T05:40:00Z"
event_date: "2026-08-13"
run_id: 2026-08-16T0411Z-intel
priority: notable
immediate_action: null
tags: [botnet, ddos, infostealer, ot-ics, vulnerabilities, cloud]
regions: [global, europe]
sectors: [technology, telco, public-sector, manufacturing]
entities: [tool:evooo1bot]
techniques: [T1190, T1110.001, T1090.002, T1040, T1573, T1543.002, T1053.003, T1037.004, T1546.004, T1497.001, T1498, T1027, T1584.005]
affected_products: ["Atlassian Confluence", "WSO2 products", "Kubernetes ingress-nginx Controller", "Zyxel firewalls", "Hikvision IP cameras", "TP-Link Archer AX21", "Tenda AC10", "NETGEAR routers", "D-Link DIR-823X", "Mitsubishi Electric ME-RTU", "Alcatel-Lucent OmniPCX Enterprise Communication Server"]
cves: []
sources:
  - url: "https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot"
    publisher: "FortiGuard Labs (Fortinet)"
    date: "2026-08-13"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/"
    publisher: "BleepingComputer"
    date: "2026-08-15"
    role: corroborating
  - url: "https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code"
    publisher: "The Record (Recorded Future News)"
    date: "2026-08-13"
    role: corroborating
closed_sources: []
evidence:
  - quote: "The embedded credential dictionary contains over 150 entries. Beyond typical IoT default credentials, the list includes service account names (jenkins, postgres, oracle, nagios, deploy) that are more common in enterprise and operations-technology environments than on consumer routers."
    publisher: "FortiGuard Labs"
  - quote: "the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities"
    publisher: "FortiGuard Labs, quoted by BleepingComputer"
verification: single-source
sourcing_note: >
  FortiGuard Labs is the originating researcher; the two corroborating outlets report that research
  rather than observing the botnet independently, so this is one assessor with additional publishers:
  single-source with corroborating republication, credibility 2, on the same basis as this window's
  Jewelbug entry. No CVE records are carried in frontmatter: the botnet's exploit module chains
  long-patched flaws whose per-CVE affected and fixed version boundaries are not stated by any source
  read here, and transcribing them from memory would be invention; the ids that matter operationally
  are named in the body against what they reach. FortiGuard's own extractable text describes targeting
  only as spanning diverse regions and gives no victim count or infected-device scale; The Record
  separately states telemetry concentrated across several regions including Europe, which could not be
  confirmed against the primary and is reported as that outlet's claim. No source names a Swiss victim
  or Swiss-specific targeting.
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Check whether any internet-facing Atlassian Confluence, WSO2 product or Kubernetes ingress-nginx admission controller in the estate is still on a version vulnerable to CVE-2022-26134, CVE-2022-29464 or CVE-2025-1974 — these are now in a commodity botnet's automated scanning arsenal rather than only a targeted-actor concern, so an instance that survived on obscurity no longer does."
migrated_from: null
---

FortiGuard Labs has documented Evooo1Bot, a previously undocumented Mirai-derived Linux botnet named after a hardcoded string present in every sample and active since at least July 2026 on the firm's own intrusion-prevention telemetry ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)). It reuses the leaked Mirai denial-of-service engine, but the researchers' summary is that it extends that framework with encrypted command-and-control, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer and an integrated exploit arsenal ([BleepingComputer, 2026-08-15](https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/)).

**The reason this is not just another Mirai fork is what the exploit module can reach.** Most of its chain is the expected consumer and small-office set — NETGEAR, Tenda, TP-Link and D-Link routers and network storage, Hikvision cameras, Telesquare gateways, and an OT remote terminal unit from Mitsubishi Electric. But three of its modules target enterprise-class, internet-facing systems that sit inside European public-sector and critical-infrastructure estates: the Atlassian Confluence OGNL injection (CVE-2022-26134), the WSO2 unrestricted-file-upload path to code execution (CVE-2022-29464), and the Kubernetes ingress-nginx admission-controller flaw (CVE-2025-1974), alongside PHP-CGI argument injection on Windows (CVE-2024-4577) and a Zyxel firewall command injection ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)). One module is a false alarm and worth naming so nobody rediscovers it and panics: the bundled Progress MOVEit Transfer code passes a payload argument without performing the upload procedure, and FortiGuard states such modules are non-exploitable as shipped ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)).

The credential dictionary points the same way. FortiGuard records over 150 entries, and notes that beyond typical IoT defaults the list carries service-account names — jenkins, postgres, oracle, nagios, deploy — that are more common in enterprise and operations-technology environments than on consumer routers ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)). The brute-forcer also screens its targets twice: it compares the SSH banner against a hardcoded list of research honeypot frameworks before attempting credentials, then after login runs a short probe reading kernel version and process-one command line and listing known honeypot install paths, aborting if the host does not answer like a real system ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)).

What the operator does with a foothold is the second half. The bot runs a SOCKS5 relay — a direct listener plus a reverse mode that separates a persistent encrypted control channel from per-session proxy data — and an HTTP credential sniffer that parses the kernel's TCP connection table to lift Basic-Auth and cookie headers into a local log. FortiGuard's framing is that transforming a compromised router into a persistent proxy lets attackers conceal their true origin and pivot into internal networks ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)). Command-and-control is encrypted and runs over TCP/443, a port FortiGuard notes is chosen to blend in with expected HTTPS traffic at the network perimeter; the researchers do not name the cipher that channel uses, though they do describe AES-256-CTR, ChaCha20 and XOR-based key derivation protecting the sample's own strings, with each key split into two constants combined at runtime. Persistence is stacked deliberately: a systemd unit impersonating an Apache cache-manager service with automatic restart, a SysV init script, a cron entry re-fetching the loader every five minutes, a profile.d injection and an rc.local append, with the process raising its own out-of-memory score adjustment and holding the watchdog device open to survive reboots and memory pressure ([FortiGuard Labs, 2026-08-13](https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot)).

**Defender takeaway:** the operational change is about who is scanning, not about a new vulnerability. Confluence and WSO2 have had fixes since 2022 and ingress-nginx since March 2025, so any exposed unpatched instance has had a long window — but those instances were previously exposed mainly to actors who chose them. They are now in a commodity botnet's automated arsenal, which scans indiscriminately and folds what it lands on into DDoS, relay and credential-collection infrastructure. The second consequence is for egress policy: a compromised host here is an exit node for someone else's traffic, so an organisation that tolerates one is lending its address space to whatever the operator relays through it.

**Triage:** the discriminators are placement rather than signature. An application server or an ingress controller is built to receive connections, so the anomaly is that host originating outbound sessions on 443 that do not correspond to any configured integration — inbound-only services initiating egress is the signal, and the encrypted transport means content inspection will not help. On embedded appliances, the persistence stack itself is the tell: a device that normally carries no cron entries, no profile.d scripts and no custom systemd units suddenly carrying all of them at once is far outside its own baseline, and the impersonating service name is designed to survive a quick eyeball rather than a comparison against what that appliance actually runs. In authentication logs, a single source cycling many distinct enterprise service-account names separates this from legitimate automation, which authenticates as one expected account. One caution for teams running SSH deception: this component fingerprints honeypots before and after login and aborts when it detects one, so silence from a deception asset is not evidence that scanning has stopped.
