FortiGuard Labs published analysis this week of Evooo1Bot, a Linux botnet it describes as a previously undocumented family. Most of the coverage files it under router botnets. That framing misses the part that matters if you run internet-facing servers: alongside the usual consumer-gateway exploits, Evooo1Bot carries an embedded exploit module aimed at software teams deploy on purpose, including Atlassian Confluence, WSO2, PHP-CGI, and Kubernetes ingress-nginx.
You cannot patch a stranger's home router. You can patch, and watch, the Confluence instance and the Kubernetes ingress in your own estate. Both sit on the same target list, which is why the interesting question here is not "another Mirai variant" but "would you notice if one of your servers joined it."
A router botnet that also hunts your app servers
The botnet reuses the leaked Mirai denial-of-service engine and bolts a lot onto it: encrypted command-and-control, an SSH brute-force scanner, a credential sniffer, a SOCKS relay, and an exploit arsenal, according to FortiGuard's writeup. The initial-access exploits hit routers and cameras from Alcatel, Netgear, Tenda, D-Link, Telesquare, Mitsubishi Electric, and Hikvision, as reported by BleepingComputer. That is the router-botnet story everyone ran.
The embedded exploit module is the part worth your attention. Four of its eight targets are server software, not appliances: Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), PHP-CGI (CVE-2024-4577), and Kubernetes ingress-nginx (CVE-2025-1974). These are the systems a self-hosting team stands up deliberately and often exposes to the internet by design.
| Product | CVE | What it hands an attacker |
|---|---|---|
| Atlassian Confluence | CVE-2022-26134 | Unauthenticated remote code execution |
| WSO2 products | CVE-2022-29464 | Arbitrary file upload to code execution |
| PHP-CGI | CVE-2024-4577 | Argument injection to code execution |
| Kubernetes ingress-nginx | CVE-2025-1974 | Configuration injection to cluster code execution |
The reframe is the point. A botnet that only ate cheap routers would be someone else's problem. This one reaches into the same rack you manage, and it does so with bugs that have public fixes. If any of those four are exposed and unpatched, you are inside its addressable market.
An exploit set that spans eighteen years
Line up the CVEs by year and the spread is striking. The oldest, CVE-2007-3010 in an Alcatel appliance, was assigned in 2007. The newest, CVE-2025-55583 in a D-Link router, landed this year. That is an eighteen-year window in a single tool.
No serious operator keeps an exploit for a 2007 bug because it is elegant. They keep it because somewhere on the internet a device that old is still answering. Evooo1Bot is not hunting for the hardest target; it is harvesting the unpatched long tail, firing everything it has and keeping whatever connects. We have watched the same economics play out with an 18-year-old Cisco flaw still being exploited and with forgotten routers pressed into scanning for attackers. The defensive lesson is not "apply the latest patch." It is asset lifecycle: the device or service you forgot to decommission is the one that gets absorbed.
Built to persist, hide, and rent your server out
Once in, Evooo1Bot behaves less like commodity malware and more like a maintained product. FortiGuard counts a 28-command remote-administration interface, C2 strings protected with layered AES and ChaCha20 keys combined at runtime, and twelve architecture-specific builds so it runs on whatever it lands on. Its SSH scanner carries more than 150 credential pairs and, tellingly, checks for over a dozen honeypot fingerprints before it commits, so researchers watching from decoy hosts get skipped.
That honeypot evasion is a maturity tell. Script-kiddie botnets do not bother; they spray and pray. Building in checks against Cowrie and Kippo means someone is protecting an operation they intend to run for a while. The credential sniffer fits the same profile: it reads /proc/net/tcp and scrapes HTTP Basic Authorization and cookie headers to /tmp/.sniff.log, quietly collecting logins that pass through the box.
The SOCKS relay is how the crew gets paid. In its reverse mode the bot dials out to an operator-controlled server and waits for session commands, turning your host into a proxy that hides the attacker's origin and lets them pivot. This is the same monetization behind a seized proxy network whose devices stayed infected and the takedown-resistant design in a botnet that hid its command channel to survive seizure. When your server becomes a relay, its traffic becomes your legal and reputational problem, whether or not you ever noticed the compromise. It is a step up from the sloppier, AI-assembled botnets we looked at earlier this year.
Hunt the persistence and the outbound proxy
You cannot patch a device you do not own, but every move Evooo1Bot makes on a host you do run is observable. Prioritize the hunt in this order:
- Outbound proxy behavior. A server with no reason to proxy that opens a listener on TCP 1080, or holds a persistent encrypted connection to an unfamiliar host, is the highest-value signal. FortiGuard names 91.92.40.118 as a C2 address; block and alert on it.
- Fake service persistence. A systemd unit you did not create describing itself as "Apache HTTPD Cache Manager" with
Restart=always, new scripts in/etc/init.d, additions to/etc/profile.d/, or an appendedrc.local. - The recurring cron job. A job firing every five minutes that pipes
wgetorcurloutput straight into a shell. - Credential theft artifacts. A new
/tmp/.sniff.log, or unexpected reads of/proc/net/tcp. - SSH brute force. Authentication failures that cycle through automation logins. The dictionary reaches past default credentials into service accounts like
postgres,jenkins,oracle,deployandnagios.
These map cleanly onto MITRE ATT&CK: brute force (T1110), systemd and cron persistence (T1543.002, T1053.003), proxy (T1090), and traffic capture (T1040). File integrity monitoring catches the persistence writes; log analysis catches the SSH storm; egress monitoring catches the relay. A managed detection and response setup pages an analyst on the combination rather than the single event, which is what separates "we caught it" from "we found it in the incident report."
The through-line across this year's botnet coverage is that the barrier to entry keeps dropping while the tooling keeps professionalizing. Evooo1Bot did not need a zero-day; it needed one exposed, unpatched service and a wide enough net. Expect the next variant to add two more server exploits and the same relay module. Decommission what you forgot, patch what is exposed, and watch your egress.