Tag: Evooo1Bot Linux botnet

New Evooo1Bot Linux botnet turns routers into traffic relay nodes
News

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

Evooo1Bot is a new modular Linux botnet malware based on Mirai that targets internet-facing gateway devices and transforms them into SOCKS5 traffic relay nodes. The malware can perform distributed denial-of-service (DDoS) attacks, SSH brute-forcing, and password theft in addition to converting computers into proxy nodes. Evooo1Bot has been using known vulnerabilities to target devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link in different locations since at least July. Fortinet researchers discovered that the malware extends the original framework with many features, such as encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,...