August 13, 2026 — A newly documented Linux-based malware variant is exploiting vulnerabilities in internet-facing routers and other network equipment while expanding the capabilities traditionally associated with the Mirai botnet.
FortiGuard Labs identified the malware as Evooo1Bot and reported that the activity has been underway for at least one month. The malware targets vulnerable hardware manufactured by Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare.
Researchers have not disclosed the number of devices believed to be compromised. FortiGuard telemetry has detected activity across North America, South America, Europe, India, China and Japan, indicating that the operation is not limited to one country or region.
Evooo1Bot spreads by exploiting unpatched vulnerabilities in internet-facing equipment. Routers and other edge devices are valuable targets because they routinely maintain network access, process large amounts of traffic and operate for extended periods without the same monitoring applied to conventional computers and servers.
The malware retains the distributed denial-of-service capabilities associated with Mirai. A compromised device can receive commands directing it to generate malicious traffic against a selected target, allowing operators to combine numerous infected systems into a coordinated attack.
Evooo1Bot extends beyond that function through encrypted command-and-control communications, network scanning, credential collection, honeypot avoidance and proxy services. Those additions make the malware useful for reconnaissance, concealed communications and follow-on network access rather than limiting it to DDoS attacks.
Its scanner searches for systems exposing Secure Shell services, which are commonly used for remote administration. The malware can also recognize signs that a device was intentionally configured as a honeypot and avoid systems designed to capture or study malicious activity.
That avoidance capability can reduce the malware’s exposure to researchers and automated threat-monitoring systems. It also indicates that Evooo1Bot’s operators are attempting to distinguish genuine devices from security traps before committing additional resources to an attempted compromise.
Evooo1Bot’s SSH scanner uses a built-in dictionary containing more than 150 credential combinations, including common IoT default credentials and service-account names used in enterprise and operational-technology environments. A separate credential-sniffing module intercepts HTTP Basic Authorization and Cookie headers and records the captured information on the compromised device.
Devices compromised through default credentials may provide the same operational value as systems breached through software vulnerabilities. Both pathways can give attackers control over hardware positioned at the boundary between a trusted network and the public internet.
Evooo1Bot also abuses the SOCKS protocol to turn infected equipment into proxy infrastructure. SOCKS allows network traffic to pass through an intermediary system, which can conceal the original source of a connection and make malicious activity appear to originate from the victim’s device.
A compromised router, firewall, internet-connected camera or other edge device could be used as a persistent proxy for additional operations. Attackers may route communications through the system, conceal command traffic, probe internal resources or conduct activity that is attributed initially to the device owner’s internet connection.
The proxy capability creates risks beyond the immediate compromise. Traffic originating through an infected device can damage the reputation of the associated internet address, trigger abuse complaints, interfere with legitimate services or complicate an investigation into unrelated malicious activity.
Access to edge equipment can also provide a pathway into connected environments when network segmentation and administrative controls are weak. The extent of that risk depends on the device configuration, available credentials, exposed services and the level of access the compromised hardware has to internal systems.
Mirai became one of the most influential botnet codebases after its source code was publicly released in 2016. Developers and criminal operators have continued adapting it to target new vulnerabilities, hardware architectures and operating environments.
Aisuru and KimWolf are among the later botnets connected to the broader Mirai lineage. Evooo1Bot reflects the same pattern of code reuse while adding functions intended to improve stealth, collect credentials and convert infected devices into operational infrastructure.
Organizations should identify every publicly accessible router, firewall, camera and embedded device under their control and compare installed firmware against current manufacturer releases. Equipment that no longer receives security updates should be removed from service or isolated from untrusted networks.
Default administrative credentials should be replaced with unique passwords. Unnecessary remote-management interfaces, exposed SSH services and unused network functions should be disabled. Administrative access should be limited to approved systems and trusted network locations.
Security teams should monitor edge devices for unexpected outbound connections, unfamiliar encrypted communications, unauthorized proxy activity, changes to administrative settings and unexplained increases in network traffic. Logs should be forwarded to a separate system when supported so attackers cannot erase the only available record by resetting the compromised device.
Suspected systems should be isolated and examined before being returned to service. A restart may interrupt some malware operating in memory, but it does not correct the vulnerability or credential weakness that allowed the compromise. Firmware updates, configuration review, credential replacement and confirmation that unauthorized access has ended are required to reduce the risk of reinfection.
Evooo1Bot demonstrates that the security risks surrounding routers and connected hardware extend beyond service-disruption attacks. A compromised edge device can become a scanner, credential collector, traffic relay, concealed access point and component of a global DDoS network while continuing to perform its ordinary functions without drawing immediate attention.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



