HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Evooo1Bot: New Mirai Variant Adds Encrypted C2, Credential Scanning, and Proxy Abuse to IoT Botnet

Researchers at FortiGuard Labs identified Evooo1Bot, a Linux‑based Mirai derivative that exploits unpatched routers and other edge hardware worldwide. The malware adds encrypted command‑and‑control, SSH scanning, and SOCKS proxy functions, enabling stealthy DDoS and pivot attacks. For SOC 2‑focused organizations, this underscores the need for robust access‑control policies and continuous monitoring of network‑edge assets.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Evooo1Bot: New Mirai Variant Adds Encrypted C2, Credential Scanning, and Proxy Abuse to IoT Botnet

What Happened — FortiGuard Labs discovered a previously undocumented Linux‑based malware family, dubbed Evooo1Bot, that builds on the Mirai code base. The variant actively exploits unpatched vulnerabilities in internet‑facing routers and other edge hardware (Alcatel, D‑Link, Mitsubishi, Netgear, Tenda, Telesquare) and adds encrypted C2 traffic, SSH scanning, default‑credential sniffing, and SOCKS‑proxy abuse. Activity has been observed across North America, South America, Europe, India, China and Japan.

Why It Matters for Compliance & Audit Readiness

  • The malware’s credential‑scanning and default‑password abuse illustrate a classic access‑control failure that SOC 2 CC6 (Logical Access) is designed to prevent and evidence.
  • Continuous monitoring of network‑edge devices and maintaining up‑to‑date firmware are required to demonstrate due diligence in a SOC 2 audit; Evooo1Bot shows the risk of gaps in those controls.

Who Is Affected — Telecommunications, ISP, cloud‑service providers, and any organization that relies on unmanaged or legacy routers, firewalls, IP cameras, or other IoT edge devices.

Recommended Actions

  • Map the incident to SOC 2 CC6 controls (access‑control policies, credential management, and privileged‑access monitoring).
  • Deploy an automated inventory and patch‑management solution for all internet‑facing hardware; capture evidence of firmware version and remediation status for audit.
  • Enforce strong, unique passwords on all edge devices and integrate credential‑rotation into your access‑control program.

Source: The Record – New Mirai variant adds stealth to botnet code

Technical Notes

  • Attack vector: exploitation of unpatched firmware bugs and default credentials (misconfiguration).
  • New capabilities: encrypted C2, SSH scanner that avoids honeypots, SOCKS proxy for persistent pivoting.
  • No specific CVE disclosed; the vulnerability stems from known vendor‑level firmware issues.
📰 Original Source
https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →