Evooo1Bot: A Sophisticated Mirai Variant Exploiting IoT Vulnerabilities
A new, highly advanced variant of the infamous **Mirai** botnet, dubbed **Evooo1Bot**, has been actively exploiting unpatched vulnerabilities in internet-facing hardware for at least a month. This Linux-based malware targets a range of routers and other devices, exhibiting capabilities far beyond its **Mirai** predecessors, including encrypted communications and sophisticated scanning techniques.
# Evooo1Bot: A Sophisticated Mirai Variant Exploiting IoT Vulnerabilities
Cybersecurity researchers at **FortiGuard Labs** have identified a new and potent **Mirai** botnet variant, **Evooo1Bot**, which has been actively compromising internet-facing hardware for at least a month. This Linux-based malware distinguishes itself with a suite of advanced features, moving beyond the typical distributed denial-of-service (DDoS) functions associated with **Mirai**.
## Targeting Unpatched Devices
**Evooo1Bot** specifically targets routers and other hardware from manufacturers including **Alcatel**, **D-Link**, **Mitsubishi Electric**, **Netgear**, **Tenda**, and **Telesquare**. The malware leverages unpatched vulnerabilities in these devices to spread and execute malicious activities. While the exact number of compromised devices worldwide remains unspecified, **FortiGuard Labs**' telemetry indicates significant activity across North America, South America, Europe, India, China, and Japan.
## Advanced Capabilities Beyond Standard Mirai
What sets **Evooo1Bot** apart from conventional **Mirai**-derived malware are its enhanced functionalities:
* **Encrypted Communications**: The botnet employs encrypted communications with its command-and-control (C2) servers, making detection and analysis more challenging.
* **Intelligent Scanner**: It includes a scanner that specifically looks for Secure Shell (SSH) code and is designed to bypass devices clearly configured as honeypots, indicating a degree of sophistication in its reconnaissance.
* **Credential Sniffer**: **Evooo1Bot** incorporates a "sniffer" to identify devices still using default access credentials, a common vulnerability in many IoT deployments.
* **SOCKS Proxy Abuse**: Arguably its most operationally significant feature, the malware abuses the widely used **SOCKS** protocol. By transforming compromised routers, firewalls, IP cameras, or other edge devices into persistent proxies, attackers can conceal their true origin, pivot into internal networks, and conduct further operations through the victim's infrastructure.
**FortiGuard Labs** emphasizes that these capabilities elevate **Evooo1Bot** significantly above the technical baseline of typical **Mirai** variants.
## The Enduring Legacy of Mirai
The source code for **Mirai** was publicly released in 2016, and in the decade since, it has served as the foundation for numerous variants. These descendants have consistently posed a significant threat to IoT security, attracting the attention of law enforcement agencies and cybersecurity specialists globally.
Recent examples include **Aisuru** and **KimWolf**, which were targeted in March by agencies from the U.S., Canada, and Germany. In May, a Canadian man was charged for his alleged involvement in operating the **KimWolf** botnet. The emergence of **Evooo1Bot** underscores the persistent challenge of securing internet-connected devices and the continuous evolution of botnet threats.