New Evooo1Bot Linux botnet turns routers into traffic relay nodes
2026-08-16T07:23:19Z•7e78830caba370dbef4aca1aa6068a06b2142e1ffc841f5ddaaf584ca6852213
AkiraClopEDR-evasionLinuxMiraiSOCKS5-proxyWindowsactive-exploitationbank-fraudbotnetcryptocurrency-frauddata-breachespionagegateway-devicesmacOSmercenary-spywareransomwareremote-code-executionrouterstraffic-relayzero-day
What happened
BleepingComputer security feed containing reports on an emerging Mirai-based Linux botnet targeting internet-facing gateway devices, active exploitation of critical vulnerabilities including SAP Commerce Cloud and macOS Screen Sharing, ransomware and data-theft activity, espionage, fraud, breaches, and newly patched Windows zero-day vulnerabilities.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7e78830caba370dbef4aca1aa6068a06b2142e1ffc841f5ddaaf584ca6852213
- Enrichment time
- 2026-08-16T07:23:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.