New Linux Botnet 'Evooo1Bot' Turns Hacked Devices Into Attacker Toolkits
Security researchers have identified a new botnet, dubbed Evooo1Bot, that builds on the notorious Mirai malware family but adds significantly more dangerous capabilities. While traditional Mirai-based botnets are mainly used to launch distributed denial-of-service (DDoS) attacks that flood websites with traffic, Evooo1Bot goes further by including exploitation modules, credential theft tools, and reverse SOCKS relays.
These added features mean that infected devices, often internet-connected routers, cameras, and other Linux-based equipment, can be turned into long-term attacker infrastructure rather than just tools for a single attack. Reverse SOCKS relays, for example, allow attackers to route malicious traffic through compromised devices, making it harder to trace attacks back to their source and giving criminals persistent access to networks.
For small and medium businesses, this development is a reminder that internet-connected devices, including routers, smart cameras, and other 'Internet of Things' equipment, are attractive targets for cybercriminals. Many of these devices ship with weak default passwords or unpatched vulnerabilities, making them easy entry points. Once compromised, they can be silently used to steal credentials or hide malicious activity, often without any visible signs of infection.