CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4546

As cited

Copy frozen at (site build).

threat intel

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

A Linux botnet called Evooo1Bot extends the Mirai framework with new modules for exploiting vulnerabilities, stealing credentials, and establishing reverse SOCKS relays. The expansion transforms infected devices from simple distributed denial-of-service (DDoS) weapons into persistent infrastructure for attackers to launch broader campaigns.

Why it matters: Linux device owners and network defenders must monitor for Evooo1Bot infections and patch known vulnerabilities, since compromised machines now serve as foothold for credential harvesting and lateral movement, not just traffic flooding.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS

The Evooo1Bot Linux botnet has added new modules that extend Mirai-like functionality, including exploitation tools, credential theft, and reverse SOCKS relays. These enhancements allow compromised devices to serve as persistent attacker infrastructure. The expansion moves beyond traditional distributed denial of service capabilities.

Why it matters: Linux device operators face increased risk of persistent compromise and lateral movement via stolen credentials and proxy relays.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary