All payload callbacks for the exploitation attempts observed by Fortinet’s FortiGuard Labs pointed to the same loader URL: 91.92.40[.]118/wget.sh, a single nexus that led analysts to a newly identified Mirai-derived Linux botnet family named “Evooo1Bot.”
Discovery and name: FortiGuard Labs' August 13 analysis
Taiwan-based researcher Yi Ping (Cara) Lin of Fortinet’s FortiGuard Labs published an analysis on August 13 identifying the new family after tracing multiple exploitation attempts to a single loader. Lin named the malware “Evooo1Bot” after the hardcoded string “evooo1” present in every binary. She assessed the botnet has been actively targeting internet-facing devices since July 2026.
Observed vulnerabilities and targeted devices
FortiGuard linked Evooo1Bot exploitation attempts to a wide array of known vulnerabilities affecting edge devices and networking equipment. The specific CVEs observed are:
- CVE-2007-3010: Alcatel OmniPCX Enterprise remote code execution
- CVE-2016-6277: NETGEAR Multiple Routers RCE
- CVE-2018-14558: Tenda AC7, AC9 and AC10 Routers command injection
- CVE-2019-14931: Mitsubishi Electric Europe B.V. ME-RTU and INEA ME-RTU remote command injection
- CVE-2020-10987: Tenda AC1900 Router AC15 Model RCE
- CVE-2021-46422: Telesquare SDT-CW3B1 command injection
- CVE-2022-37055: D-Link Routers buffer overflow
- CVE-2024-29269: Telesquare TLR-2005KSH command injection
- CVE-2025-10123: D-Link DIR-823X command injection
- CVE-2025-55583: D-Link DIR-868L B1 router command injection
FortiGuard observed that all exploitation payloads referenced the same loader URL, tying these diverse attempts to a single loader and a common malware family.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildMirai lineage and code reuse
Evooo1Bot reuses the distributed denial-of-service (DDoS) engine from publicly leaked Mirai source code. The FortiGuard write-up notes Mirai’s origin in a September 2016 source-code release on Hack Forums by user “Anna-senpai,” a leak later identified by the FBI as tied to Paras Jha and co-creators Josiah White and Dalton Norman. While Evooo1Bot builds on Mirai’s DDoS framework, Lin emphasizes that the new family substantially extends that baseline.
Expanded capabilities beyond conventional Mirai variants
FortiGuard’s analysis lists several significant enhancements in Evooo1Bot’s feature set:
- Encrypted command-and-control (C2) communications and a 28-command remote administration interface
- An SSH brute-force scanner
- A reverse SOCKS relay module
- Multiple layers of string obfuscation using AES-256-CTR, ChaCha20 and XOR-based key derivation
- A credential sniffer
- An integrated exploit arsenal targeting multiple known vulnerabilities across IoT devices, networking equipment and enterprise applications
Lin wrote that “These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware.”
SOCKS relay module: turning compromised devices into persistent proxies
FortiGuard singled out the reverse SOCKS relay as “arguably the most operationally significant” feature. According to Lin, the SOCKS relay can transform a compromised edge device into a persistent proxy, allowing an attacker to “conceal their true origin, pivot into internal networks and conduct follow-on operations through the victim's infrastructure.” That shift—compromise plus covert relay—changes a device from a transient DDoS asset into a stalking horse for further intrusion activity.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: FortiGuard’s findings tie diverse vulnerability exploitation to one loader URL (91.92.40[.]118/wget.sh) and one malware family, meaning defenders will be watching for callbacks and exploit attempts that match the listed CVEs and the malware’s distinct communication and obfuscation patterns.
- Procurement and device owners: The observed CVEs name specific vendor models and product classes (Alcatel OmniPCX Enterprise, NETGEAR routers, Tenda models, Mitsubishi ME-RTU devices, Telesquare models, and several D-Link routers), underlining the need to review affected equipment and firmware status where those products are in use.
- End users and administrators of internet-facing devices: FortiGuard’s timeline places active targeting beginning in July 2026, underscoring that internet-exposed edge devices remain an operational focus for attackers leveraging Mirai-class toolsets.
Evooo1Bot demonstrates how a decades-old leak can seed successive waves of innovation: researchers at FortiGuard traced a coordinated set of exploit attempts back to a single loader URL and a new code family that grafts modern proxying, encrypted C2 and multi-layer obfuscation onto Mirai’s DDoS core. As Lin concludes, the combination of a broad exploit portfolio and a reverse SOCKS relay puts Evooo1Bot “well beyond the technical baseline of conventional Mirai-derived malware.”
Read the original FortiGuard–reported analysis: https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/




