Evooo1Bot is a previously undocumented Mirai-based malware variant that has been actively exploiting unpatched internet-facing devices from multiple hardware vendors for at least a month. It adds encrypted command-and-control communications, SSH scanning, honeypot avoidance, credential sniffing, and SOCKS proxy abuse to help attackers hide their origin and pivot through compromised infrastructure. #Evooo1Bot #Mirai #FortiGuardLabs #Alcatel #DLink #MitsubishiElectric #Netgear #Tenda #Telesquare
Keypoints
- Evooo1Bot is a new Linux-based malware derived from Mirai.
- It targets routers and other hardware from several vendors.
- Unpatched vulnerabilities let it spread and run malicious activity.
- It includes encrypted C2, SSH scanning, and honeypot detection.
- It abuses SOCKS proxies to hide attacker traffic and reach internal networks.
Read More: https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code