New Mirai variant adds stealth capabilities to notorious botnet code

Malware that adds multiple capabilities to the infamous Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, researchers said Thursday.
Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs.
Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said. Evooo1Bot appears to be previously undocumented, they said.
The report does not specify how many devices have been compromised worldwide, but the company’s telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan.
Beyond Mirai’s usual distributed denial-of-service (DDoS) functions, Evooo1Bot’s features include encrypted communications with command-and-control servers; a scanner that looks for Secure Shell (SSH) code and skips devices clearly set up as honeypots for malicious traffic; and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service.
“These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” FortiGuard Labs said.
The malware also abuses the widely used SOCKS protocol that allows devices to connect with servers through a proxy. That capability “is arguably the most operationally significant,” FortiGuard Labs said. “By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure.”
The source code for Mirai was publicly released in 2016, and in the decade since, it has served as the basis for numerous variants that have drawn the attention of law enforcement agencies and cybersecurity specialists.
Descendants such as Aisuru and KimWolf were targeted by agencies from the U.S., Canada and Germany in March. A Canadian man was charged in May with running KimWolf.
References in this story
- Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs www.fortinet.com FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays…
- Source Code for IoT Botnet ‘Mirai’ Released – Krebs on Security krebsonsecurity.com
- Mirai and Its Heirs: A Decade of Structural Neglect in IoT Security - Censys censys.com A deep look at how Mirai and its descendents have evolved over the past decade — and why the botnet's methodology still works today.
- US seizes domains and infrastructure used in sprawling botnet campaigns therecord.media The Justice Department said on Thursday evening that the Aisuru, KimWolf, JackSkid and Mossad botnets were used to target victims with distributed denial-of-service (DDoS) attacks that overloaded websites and made them…
- Canadian man arrested, charged for running KimWolf DDos botnet therecord.media In court documents unsealed on Thursday, the Justice Department said Jacob Butler ran KimWolf as a DDoS-for-hire service that infected over a million devices worldwide.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Joe Warminsky (@jwarminsky.bsky.social) bsky.app News Editor at The Record: @therecordmedia.bsky.social [ Tired of bios ] [ Often thinking about music ] [ Etc. ]



