๐จ ACTIVE EXPLOITATION
- Evooo1Bot Mirai Botnet Hijacks Routers as SOCKS5 Relay Nodes
Evooo1Bot is exploiting internet-facing edge devices to build a Linux botnet.
- Targets internet-facing routers, firewalls and IoT devices from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare.
- Exploited CVEs include CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931 and CVE-2020-10987.
- Additional targets include CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123 and CVE-2025-55583.
- Exploitation downloads architecture-matched binaries through 91.92.40[.]118/wget.sh using wget, BusyBox wget, curl or TFTP.
- The Mirai-derived botnet uses encrypted C2, SSH scanning, honeypot checks, credential sniffing, DDoS modules and persistent SOCKS5 relays. ๐ Source: fortinet.com ยท ๐ Coverage: infosecurity-magazine.com ยท ๐ via BleepingComputer