The threat targets internet-facing routers, firewalls, cameras, and other edge devices, turning compromised systems into tools for DDoS attacks, SOCKS5 proxy relays, credential theft, and further network intrusion.
Evooo1Bot borrows its DDoS engine from the leaked Mirai source code but adds a broader set of functions.
These include encrypted command-and-control (C2) communication, SSH brute-force scanning, traffic sniffing, remote shell access, file transfers, persistence, and an exploit module that targets known vulnerabilities.
FortiGuard telemetry shows the campaign has been active since July 2026. Researchers observed exploit attempts that downloaded payloads from 91.92.40[.]118/wget.sh.
The script detects a target device’s CPU architecture, downloads the matching Linux binary, grants execution permission, and runs it. It also clears Bash history after infection to reduce evidence.

The botnet targets several older and newer flaws affecting networking products. Observed targets include Alcatel OmniPCX, NETGEAR routers, Tenda routers, Mitsubishi Electric devices, Telesquare products, and multiple D-Link models.
Campaign labels in download commands suggest that operators monitor infection success by vulnerability and device type.
Evooo1Bot Hijacks Network Defenses
Evooo1Bot uses several layers of protection to hide strings and operational details inside its binaries. It encrypts configuration data with AES, ChaCha20, and XOR-based routines.
Encryption keys are split into separate data blocks and reconstructed only while the malware is running.
Before connecting to its C2 server, Evooo1Bot looks for signs that it is being analyzed. It checks for tools such as GDB, Wireshark, tcpdump, IDA, Ghidra, YARA, and Valgrind.
It also searches for sandbox, virtual machine, and container indicators linked to VMware, VirtualBox, QEMU, Docker-like environments, and malware-analysis platforms.

If these checks are passed, the bot contacts its C2 infrastructure over TCP port 443. Using this common HTTPS port may help its traffic blend into normal encrypted network activity.
The malware supports remote commands for system information collection, process termination, self-updates, file uploads and downloads, and interactive shell access. It can establish a pseudo-terminal for attackers and run commands in the background.
Its persistence module installs multiple startup methods at once. These include a fake systemd service described as “Apache HTTPD Cache Manager,” SysV init scripts, cron jobs, shell-profile modifications, and rc.local changes.
The bot also attempts to survive resource pressure by adjusting its out-of-memory killer score and keeping a watchdog device open, fortinet said.
Indicators of Compromise
| IOC Type | Indicator | Description |
|---|---|---|
| C2 / Payload Server IP | 91.92.40[.]118 | Evooo1Bot command-and-control and payload-hosting infrastructure |
| Loader URL | http://91.92.40[.]118/wget.sh | Script used to download and execute architecture-specific bot binari |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR