threat-intel Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS Evooo1Bot, a Linux botnet derived from Mirai, has significantly expanded its capabilities beyond simple DDoS attacks. It now incorporates advanced features like encrypted C2 communications, SSH brute-force scanning, a reverse SOCKS relay module, and a credential sniffer, effectively transforming compromised devices int… Dark Reading · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558miraiddosbotnet
threat-intel Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies A new Linux botnet, dubbed Evooo1Bot, leveraging Mirai's code, is actively exploiting vulnerabilities in internet-facing devices to turn them into SOCKS5 proxies. The botnet utilizes a range of capabilities including enc… The Hacker News · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558botnetsocks5proxy
threat-intel New Mirai variant adds stealth capabilities to notorious botnet code A new, stealthier variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for over a month. This malware boasts advanced features like encrypted communicati… The Record · Aug 13, 2026 High CACHGEmiraibotnetvulnerability
threat-intel Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process A new Mirai-derived botnet, Tengu, is leveraging hardware watchdog timers and other persistence mechanisms to re-establish itself on compromised Linux devices, even after defenders attempt to kill its main process. The b… The Hacker News · Jul 28, 2026 High botnetmiraiiot
threat-intel Anti-DDoS Firm Heaped Attacks on Brazilian ISPs A Brazilian DDoS protection firm, Huge Networks, was found to be running a botnet that launched massive DDoS attacks against Brazilian ISPs. This activity stemmed from a security breach in January 2026 that compromised t… Krebs on Security · Apr 30, 2026 High CVE-2023-1389BRUSddosbotnetdns
threat-intel A Deep Dive Into Attempted Exploitation of CVE-2023-33538 This report details an ongoing attempt to exploit CVE-2023-33538, a vulnerability in older TP-Link Wi-Fi router models (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10). Automated scans, utilizing Mirai-like malware p… Palo Alto Unit 42 · Apr 16, 2026 High CVE-2023-33538USiotvulnerabilitymirai