The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.

August 17, 2026

Yet another Mirai-derived botnet is on the loose, targeting Linux systems by exploiting flaws in various Internet-facing devices to combine distributed denial of service (DDoS) attacks with a broader set of malicious capabilities.

The botnet, tracked as "Evooo1Bot" by the research team at Fortiguard Labs, has been actively targeting Internet-facing devices — including equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — since at least July, according to a report published Friday.

"Evooo1Bot is a Linux botnet family that incorporates the Mirai DDoS engine into a significantly more capable and modular framework," Fortiguard Labs threat researcher Cara Lin explained in the report.