Home/ Blog/ Security news/ Article
Blog · Security news

Evooo1Bot botnet turns exposed Linux servers into credential-stealing proxies

Evooo1Bot is a new Linux botnet exploiting Confluence, WSO2 and ingress-nginx, then stealing credentials and turning servers into proxies. Detect it now.

Isometric network nodes linked by thin threads routing through one raised node

FortiGuard Labs published analysis this week of Evooo1Bot, a Linux botnet it describes as a previously undocumented family. Most of the coverage files it under router botnets. That framing misses the part that matters if you run internet-facing servers: alongside the usual consumer-gateway exploits, Evooo1Bot carries an embedded exploit module aimed at software teams deploy on purpose, including Atlassian Confluence, WSO2, PHP-CGI, and Kubernetes ingress-nginx.

You cannot patch a stranger's home router. You can patch, and watch, the Confluence instance and the Kubernetes ingress in your own estate. Both sit on the same target list, which is why the interesting question here is not "another Mirai variant" but "would you notice if one of your servers joined it."

A router botnet that also hunts your app servers

The botnet reuses the leaked Mirai denial-of-service engine and bolts a lot onto it: encrypted command-and-control, an SSH brute-force scanner, a credential sniffer, a SOCKS relay, and an exploit arsenal, according to FortiGuard's writeup. The initial-access exploits hit routers and cameras from Alcatel, Netgear, Tenda, D-Link, Telesquare, Mitsubishi Electric, and Hikvision, as reported by BleepingComputer. That is the router-botnet story everyone ran.

The embedded exploit module is the part worth your attention. Four of its eight targets are server software, not appliances: Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), PHP-CGI (CVE-2024-4577), and Kubernetes ingress-nginx (CVE-2025-1974). These are the systems a self-hosting team stands up deliberately and often exposes to the internet by design.

ProductCVEWhat it hands an attacker
Atlassian ConfluenceCVE-2022-26134Unauthenticated remote code execution
WSO2 productsCVE-2022-29464Arbitrary file upload to code execution
PHP-CGICVE-2024-4577Argument injection to code execution
Kubernetes ingress-nginxCVE-2025-1974Configuration injection to cluster code execution
Four of the eight vulnerabilities in Evooo1Bot's embedded exploit module target server software, not consumer routers. Source: FortiGuard Labs.

The reframe is the point. A botnet that only ate cheap routers would be someone else's problem. This one reaches into the same rack you manage, and it does so with bugs that have public fixes. If any of those four are exposed and unpatched, you are inside its addressable market.

An exploit set that spans eighteen years

Line up the CVEs by year and the spread is striking. The oldest, CVE-2007-3010 in an Alcatel appliance, was assigned in 2007. The newest, CVE-2025-55583 in a D-Link router, landed this year. That is an eighteen-year window in a single tool.

No serious operator keeps an exploit for a 2007 bug because it is elegant. They keep it because somewhere on the internet a device that old is still answering. Evooo1Bot is not hunting for the hardest target; it is harvesting the unpatched long tail, firing everything it has and keeping whatever connects. We have watched the same economics play out with an 18-year-old Cisco flaw still being exploited and with forgotten routers pressed into scanning for attackers. The defensive lesson is not "apply the latest patch." It is asset lifecycle: the device or service you forgot to decommission is the one that gets absorbed.

Built to persist, hide, and rent your server out

Once in, Evooo1Bot behaves less like commodity malware and more like a maintained product. FortiGuard counts a 28-command remote-administration interface, C2 strings protected with layered AES and ChaCha20 keys combined at runtime, and twelve architecture-specific builds so it runs on whatever it lands on. Its SSH scanner carries more than 150 credential pairs and, tellingly, checks for over a dozen honeypot fingerprints before it commits, so researchers watching from decoy hosts get skipped.

That honeypot evasion is a maturity tell. Script-kiddie botnets do not bother; they spray and pray. Building in checks against Cowrie and Kippo means someone is protecting an operation they intend to run for a while. The credential sniffer fits the same profile: it reads /proc/net/tcp and scrapes HTTP Basic Authorization and cookie headers to /tmp/.sniff.log, quietly collecting logins that pass through the box.

The SOCKS relay is how the crew gets paid. In its reverse mode the bot dials out to an operator-controlled server and waits for session commands, turning your host into a proxy that hides the attacker's origin and lets them pivot. This is the same monetization behind a seized proxy network whose devices stayed infected and the takedown-resistant design in a botnet that hid its command channel to survive seizure. When your server becomes a relay, its traffic becomes your legal and reputational problem, whether or not you ever noticed the compromise. It is a step up from the sloppier, AI-assembled botnets we looked at earlier this year.

Hunt the persistence and the outbound proxy

You cannot patch a device you do not own, but every move Evooo1Bot makes on a host you do run is observable. Prioritize the hunt in this order:

  • Outbound proxy behavior. A server with no reason to proxy that opens a listener on TCP 1080, or holds a persistent encrypted connection to an unfamiliar host, is the highest-value signal. FortiGuard names 91.92.40.118 as a C2 address; block and alert on it.
  • Fake service persistence. A systemd unit you did not create describing itself as "Apache HTTPD Cache Manager" with Restart=always, new scripts in /etc/init.d, additions to /etc/profile.d/, or an appended rc.local.
  • The recurring cron job. A job firing every five minutes that pipes wget or curl output straight into a shell.
  • Credential theft artifacts. A new /tmp/.sniff.log, or unexpected reads of /proc/net/tcp.
  • SSH brute force. Authentication failures that cycle through automation logins. The dictionary reaches past default credentials into service accounts like postgres, jenkins, oracle, deploy and nagios.

These map cleanly onto MITRE ATT&CK: brute force (T1110), systemd and cron persistence (T1543.002, T1053.003), proxy (T1090), and traffic capture (T1040). File integrity monitoring catches the persistence writes; log analysis catches the SSH storm; egress monitoring catches the relay. A managed detection and response setup pages an analyst on the combination rather than the single event, which is what separates "we caught it" from "we found it in the incident report."

The through-line across this year's botnet coverage is that the barrier to entry keeps dropping while the tooling keeps professionalizing. Evooo1Bot did not need a zero-day; it needed one exposed, unpatched service and a wide enough net. Expect the next variant to add two more server exploits and the same relay module. Decommission what you forgot, patch what is exposed, and watch your egress.

Topics

Frequently asked questions

What is Evooo1Bot?

Evooo1Bot is a Mirai-based Linux botnet documented by FortiGuard Labs in 2026. It exploits internet-facing devices and servers, then installs an SSH scanner, a credential sniffer, and a SOCKS proxy module that turns each compromised host into a relay for concealing malicious traffic.

Which systems does Evooo1Bot target?

It targets internet-facing gateways and servers. Beyond routers from D-Link, Netgear and Tenda, its embedded exploit module reaches server software including Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), PHP-CGI (CVE-2024-4577), and Kubernetes ingress-nginx (CVE-2025-1974).

How do I detect Evooo1Bot on a Linux server?

Look for persistence it installs: a systemd service falsely named Apache HTTPD Cache Manager, new init scripts, profile.d entries, and a cron job every five minutes piping downloads into a shell. Also watch for outbound proxy connections and SSH brute-force attempts against service accounts.

Is Evooo1Bot being actively exploited?

Yes. FortiGuard Labs reports Evooo1Bot has been active since at least July 2026, exploiting known vulnerabilities across multiple regions. The flaws it uses are already patched, so exposure comes from unpatched or end-of-life devices and servers still reachable from the internet.

What does the SOCKS relay in Evooo1Bot do?

The SOCKS module turns a compromised host into a proxy. In reverse mode the bot dials out to an operator's relay server and waits for session commands, letting attackers route traffic through your machine to hide their origin and pivot into internal networks.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.