Evooo1Bot: New Mirai Variant Adds Encrypted C2, Credential Scanning, and Proxy Abuse to IoT Botnet
What Happened — FortiGuard Labs discovered a previously undocumented Linux‑based malware family, dubbed Evooo1Bot, that builds on the Mirai code base. The variant actively exploits unpatched vulnerabilities in internet‑facing routers and other edge hardware (Alcatel, D‑Link, Mitsubishi, Netgear, Tenda, Telesquare) and adds encrypted C2 traffic, SSH scanning, default‑credential sniffing, and SOCKS‑proxy abuse. Activity has been observed across North America, South America, Europe, India, China and Japan.
Why It Matters for Compliance & Audit Readiness
- The malware’s credential‑scanning and default‑password abuse illustrate a classic access‑control failure that SOC 2 CC6 (Logical Access) is designed to prevent and evidence.
- Continuous monitoring of network‑edge devices and maintaining up‑to‑date firmware are required to demonstrate due diligence in a SOC 2 audit; Evooo1Bot shows the risk of gaps in those controls.
Who Is Affected — Telecommunications, ISP, cloud‑service providers, and any organization that relies on unmanaged or legacy routers, firewalls, IP cameras, or other IoT edge devices.
Recommended Actions
- Map the incident to SOC 2 CC6 controls (access‑control policies, credential management, and privileged‑access monitoring).
- Deploy an automated inventory and patch‑management solution for all internet‑facing hardware; capture evidence of firmware version and remediation status for audit.
- Enforce strong, unique passwords on all edge devices and integrate credential‑rotation into your access‑control program.
Source: The Record – New Mirai variant adds stealth to botnet code
Technical Notes
- Attack vector: exploitation of unpatched firmware bugs and default credentials (misconfiguration).
- New capabilities: encrypted C2, SSH scanner that avoids honeypots, SOCKS proxy for persistent pivoting.
- No specific CVE disclosed; the vulnerability stems from known vendor‑level firmware issues.