hacker-news · Crawled Aug 17, 2026

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

2 IoCs 3 CVEs
Read original article ↗

AI Summary

Evooo1Bot is a newly identified Linux botnet derived from Mirai source code that targets internet-facing edge devices by exploiting known vulnerabilities. It installs a SOCKS5 proxy on compromised systems, enabling threat actors to route traffic through infected devices for evasion and anonymity. The malware includes an exploit toolkit targeting multiple CVEs, performs anti-analysis checks, and communicates with C2 servers over encrypted channels on port 443. It supports various post-compromise actions including DDoS attacks, credential sniffing, SSH brute-forcing, and lateral movement.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 2 extracted

Type Value Detail
IP 91[.]92[.]40[.]118 Details →
Filename wget.sh Details →

MITRE ATT&CK TTPs 19 techniques