Evooo1Bot Linux botnet hijacks exposed devices
A Linux botnet called Evooo1Bot steals control of unsecured edge devices, like routers, cameras, or IoT gadgets, to launch attacks, steal data, or hide its operators. It uses weak passwords and old security flaws to break in, then turns the device into a tool for disruption.
- Report priority
- Medium
- Targets
- Edge devices
How it works
Attackers scan for Linux edge devices with weak SSH passwords or unpatched flaws, then send a malicious script that secretly takes over the device and connects it to a hidden command server.
What to do
Check if you have any Linux edge devices, like routers, cameras, or IoT gadgets, connected directly to the internet and running outdated software or default SSH passwords.
Update all Linux edge devices to the latest software, change default SSH passwords, and disable remote SSH access if possible. Use a firewall to block unnecessary internet-facing ports.
Technical details
An attacker scans the internet for Linux devices with default SSH passwords or outdated software. When they find one, they send a fake login prompt with hidden code. The device accepts it without warning, then starts sending traffic to the attacker's servers. The attacker now uses that device to launch attacks on others or hide their own location.
Evooo1Bot is a Linux-based botnet targeting exposed edge devices by exploiting unpatched vulnerabilities and brute-forcing weak SSH credentials. Once inside, attackers establish encrypted command-and-control (C&C) access, enabling remote control, credential theft, file transfers, and proxy relay. The botnet combines elements from the leaked Mirai source code with additional functions for proxy abuse, credential sniffing, and exploit delivery, expanding its capabilities beyond basic DDoS attacks.
The malware incorporates 16 distinct DDoS attack methods, including UDP floods, DNS amplification, SYN attacks, GRE floods, and fragmented TCP strikes. It also features an exploit dispatcher targeting known vulnerabilities in devices from vendors like D-Link, Tenda, Hikvision, Zyxel, and TP-Link. After compromise, the botnet loads a processor-specific binary, clears Bash history, and establishes persistence via system services, startup scripts, and scheduled tasks.
Active exploitation attempts were observed against internet-facing devices starting in July 2026.
References
- fortinet.com · multi-functional-linux-botnet-evooo1bot Cyber Security News
- ppl-ai-file-upload.s3.amazonaws.com · Evooo1Bot-Linux-Botnet-Uses-16-DDoS-Methods-and-SOCKS5-Proxies-to-Hijack-Edge-Devices.pdf Cyber Security News
- any.run · threat-intelligence-feeds Cyber Security News
- bleepingcomputer.com · new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes BleepingComputer
- infosecurity-magazine.com · new-linux-botnet-evooo1bot-victims Infosecurity Magazine
- thehackernews.com · ai-assisted-http-terminator-finds-novel.html TheHackerNews
- infosecurity-magazine.com · xmrig-linux-pam-forensic Infosecurity Magazine
- exploit-db.com · 52643 Exploit-DB