New Mirai variant adds stealth capabilities to notorious botnet code
Malware that adds multiple capabilities to the infamous Mirai botnet code has been actively exploiting vulnerabilities in internet-facing hardware for at least a month, researchers said Thursday.
Dubbed Evooo1Bot, the Linux-based malware targets routers and other hardware from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare, according to researchers at FortiGuard Labs.
Unpatched bugs in those devices allow Evooo1Bot to spread and carry out potential malicious activity, the researchers said. Evooo1Bot appears to be previously undocumented, they said.
The report does not specify how many devices have been compromised worldwide, but the company’s telemetry shows activity concentrated in North America, South America, Europe, India, China and Japan.
Beyond Mirai’s usual distributed denial-of-service (DDoS) functions, Evooo1Bot’s features include encrypted communications with command-and-control servers; a scanner that looks for Secure Shell (SSH) code and skips devices clearly set up as honeypots for malicious traffic; and a “sniffer” that looks for default access credentials that haven’t been changed since a device was put into service.
“These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” FortiGuard Labs said.
The malware also abuses the widely used SOCKS protocol that allows devices to connect with servers through a proxy. That capability “is arguably the most operationally significant,” FortiGuard Labs said. “By transforming a compromised router, firewall, IP camera, or other edge device into a persistent proxy, the malware enables attackers to conceal their true origin, pivot into internal networks, and conduct follow-on operations through the victim's infrastructure.”
The source code for Mirai was publicly released in 2016, and in the decade since, it has served as the basis for numerous variants that have drawn the attention of law enforcement agencies and cybersecurity specialists.
Descendants such as Aisuru and KimWolf were targeted by agencies from the U.S., Canada and Germany in March. A Canadian man was charged in May with running KimWolf.
Joe Warminsky
has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.



