<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr" -->

---
title: Multi-Functional Linux Botnet “Evooo1Bot” | daily.dev
description: FortiGuard Labs documents a newly discovered Linux botnet dubbed Evooo1Bot, which extends the leaked Mirai DDoS engine with encrypted C2 communications, an SSH...
canonical: https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Multi-Functional Linux Botnet “Evooo1Bot” | daily.dev
og:description: FortiGuard Labs documents a newly discovered Linux botnet dubbed Evooo1Bot, which extends the leaked Mirai DDoS engine with encrypted C2 communications, an SSH...
og:url: https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr
og:image: https://api.daily.dev/og/posts/F0yleDZLr.png
og:image:alt: Multi-Functional Linux Botnet “Evooo1Bot”
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Multi-Functional Linux Botnet “Evooo1Bot”

**[FortiGuard Threat Research](https://daily.dev/sources/fortiguard-threat-research)** · 12 min read · 0 upvotes · 0 comments

## Summary

FortiGuard Labs documents a newly discovered Linux botnet dubbed Evooo1Bot, which extends the leaked Mirai DDoS engine with encrypted C2 communications, an SSH brute-force scanner with honeypot detection, a reverse SOCKS5 relay module, a credential sniffer, and an integrated exploit arsenal covering ten actively-exploited CVEs plus eight additional CVE payload entries (some non-functional). Active since July 2026, it targets IoT devices, routers, and enterprise appliances across multiple regions, using a loader script served from a hardcoded IP that fetches architecture-matched binaries. The malware employs multi-layer string obfuscation (AES-256-CTR, ChaCha20, XOR) and extensive anti-analysis/anti-sandbox checks, and installs five persistence mechanisms simultaneously. Fortinet provides detection signatures, IPS rules, and IOCs, and recommends prompt patching of Internet-facing devices.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://feeds.fortinet.com/~/967797734/0/fortinet/blog/threat-research~MultiFunctional-Linux-Botnet-%E2%80%9CEvoooBot%E2%80%9D>

## Questions this post answers

### What is the Evooo1Bot Linux botnet and what capabilities does it have?

Evooo1Bot is a Linux botnet that extends the leaked Mirai DDoS engine with encrypted C2 communications, an SSH brute-force scanner with honeypot evasion, a SOCKS5 relay module (direct and reverse modes), a credential sniffer reading HTTP Basic Auth and Cookie headers, and a 28-command remote administration interface including a CVE exploit dispatcher. It has been active since July 2026.

_Track emerging botnet threats and IoT vulnerability exploitation trends on daily.dev to stay ahead of exposure risks._

### Which CVEs is the Evooo1Bot botnet actively exploiting to infect devices?

Active exploitation was observed for ten CVEs including CVE-2007-3010 (Alcatel OmniPCX), CVE-2016-6277 (NETGEAR routers), CVE-2018-14558 and CVE-2020-10987 (Tenda routers), CVE-2019-14931 (Mitsubishi ME-RTU), CVE-2021-46422 and CVE-2024-29269 (Telesquare), CVE-2022-37055, CVE-2025-10123, and CVE-2025-55583 (D-Link routers), all pointing to the same loader URL at 91.92.40.118/wget.sh.

_Security teams patching edge devices against known CVEs can follow botnet exploitation trends via daily.dev._

### How does the SSH scanner in the Evooo1Bot botnet detect and avoid honeypots?

It runs two checks before delivering payloads: a pre-authentication banner comparison against known honeypot signatures like Cowrie, Kippo, HonSSH, and Glutton, and a post-login probe that runs a shell command checking /proc/version for the string 'Linux version' and scanning for /opt/cowrie or /home/kippo directories. Only targets passing both checks, plus a valid credential from a 150+ entry dictionary, receive the persistence payload.

_Understanding honeypot-evasion tactics like these helps defenders on daily.dev refine SSH-facing detection strategies._

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#linux](https://daily.dev/tags/linux)

[View this post on daily.dev](https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Multi-Functional Linux Botnet “Evooo1Bot”","url":"https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr"},"datePublished":"2026-08-13T13:05:06.296Z","dateModified":"2026-08-17T16:13:35.338Z","description":"FortiGuard Labs documents a newly discovered Linux botnet dubbed Evooo1Bot, which extends the leaked Mirai DDoS engine with encrypted C2 communications, an SSH...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4dc0546ccc84b584140792ae5004b827?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4dc0546ccc84b584140792ae5004b827?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"FortiGuard Threat Research","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"FortiGuard Threat Research","logo":"https://media.daily.dev/image/upload/s--g8QQFZ6i--/f_auto,q_auto/v1780213347/logos/fortiguard-threat-research?_a=BAMAMiWQ0","url":"https://daily.dev/sources/fortiguard-threat-research"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,linux","timeRequired":"PT12M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"FortiGuard Threat Research","item":"https://daily.dev/sources/fortiguard-threat-research"},{"@type":"ListItem","position":3,"name":"Multi-Functional Linux Botnet “Evooo1Bot”"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/multi-functional-linux-botnet-evooo1bot--f0yledzlr#faq","mainEntity":[{"@type":"Question","name":"What is the Evooo1Bot Linux botnet and what capabilities does it have?","acceptedAnswer":{"@type":"Answer","text":"Evooo1Bot is a Linux botnet that extends the leaked Mirai DDoS engine with encrypted C2 communications, an SSH brute-force scanner with honeypot evasion, a SOCKS5 relay module (direct and reverse modes), a credential sniffer reading HTTP Basic Auth and Cookie headers, and a 28-command remote administration interface including a CVE exploit dispatcher. It has been active since July 2026. Track emerging botnet threats and IoT vulnerability exploitation trends on daily.dev to stay ahead of exposure risks."}},{"@type":"Question","name":"Which CVEs is the Evooo1Bot botnet actively exploiting to infect devices?","acceptedAnswer":{"@type":"Answer","text":"Active exploitation was observed for ten CVEs including CVE-2007-3010 (Alcatel OmniPCX), CVE-2016-6277 (NETGEAR routers), CVE-2018-14558 and CVE-2020-10987 (Tenda routers), CVE-2019-14931 (Mitsubishi ME-RTU), CVE-2021-46422 and CVE-2024-29269 (Telesquare), CVE-2022-37055, CVE-2025-10123, and CVE-2025-55583 (D-Link routers), all pointing to the same loader URL at 91.92.40.118/wget.sh. Security teams patching edge devices against known CVEs can follow botnet exploitation trends via daily.dev."}},{"@type":"Question","name":"How does the SSH scanner in the Evooo1Bot botnet detect and avoid honeypots?","acceptedAnswer":{"@type":"Answer","text":"It runs two checks before delivering payloads: a pre-authentication banner comparison against known honeypot signatures like Cowrie, Kippo, HonSSH, and Glutton, and a post-login probe that runs a shell command checking /proc/version for the string 'Linux version' and scanning for /opt/cowrie or /home/kippo directories. Only targets passing both checks, plus a valid credential from a 150+ entry dictionary, receive the persistence payload. Understanding honeypot-evasion tactics like these helps defenders on daily.dev refine SSH-facing detection strategies."}}]}
```

