A new strain of malware, named Evooo1Bot, has emerged and is actively exploiting vulnerabilities in internet-facing hardware, enhancing the capabilities of the notorious Mirai botnet. Researchers from FortiGuard Labs revealed that this Linux-based malware targets devices from well-known brands, including Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare. These devices, when left unpatched, become susceptible to Evooo1Bot, which allows the malware to spread and potentially execute malicious activities. Although the exact number of affected devices worldwide remains unspecified, telemetry data indicates significant activity in regions like North America, South America, Europe, India, China, and Japan.

Evooo1Bot goes beyond the typical distributed denial-of-service functionalities associated with Mirai. It introduces encrypted communications with command-and-control servers, a scanner that identifies Secure Shell (SSH) codes while avoiding honeypots, and a credential 'sniffer' that targets devices with default access credentials. FortiGuard Labs noted that these features push Evooo1Bot beyond the usual technical scope of Mirai-based malware.

Significantly, Evooo1Bot exploits the SOCKS protocol, a common method for devices to connect to servers through a proxy. This capability is considered highly operationally significant because it allows compromised devices to function as persistent proxies. As a result, attackers can mask their true origin, infiltrate internal networks, and carry out further operations using the victim's infrastructure.

Since the public release of Mirai's source code in 2016, numerous variants have emerged, drawing attention from cybersecurity experts and law enforcement. Variants such as Aisuru and KimWolf were targeted by agencies from the U.S., Canada, and Germany earlier this year. In May, a Canadian man faced charges related to operating KimWolf, highlighting the ongoing threat posed by these evolving malware strains.