Evooo1Bot turns hacked routers into DDoS weapons

Published August 14, 2026

Evooo1Bot is a Linux botnet that hijacks routers, cameras, and enterprise gear to flood websites, steal passwords, and hide its own attacks. Attackers send fake login prompts to trick users into installing it.

Report priority
Medium
Targets
routers+2 more

How it works

Attackers send fake login prompts to users of vulnerable Linux routers, cameras, and enterprise systems, tricking them into installing Evooo1Bot malware that turns their device into a DDoS weapon and password thief.

What to do

Check if your Linux router, camera, or enterprise device has been hacked by looking for unusual network traffic or unexpected login prompts.

Update your Linux device's firmware immediately and enable strong SSH passwords or disable remote login if possible.

Technical details

Affected software: routers, cameras, enterprise systems

An attacker sends a fake SSH login prompt to a Linux router admin. The admin types their password, which Evooo1Bot steals. The malware then forces the router to attack other websites, hide the attacker's real IP, and spread to other devices.

A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems, combining Mirai-derived DDoS capabilities with proxy relaying, credential theft, SSH brute forcing, and exploit-driven propagation.