A new variant of the notorious Mirai botnet malware, dubbed Evooo1Bot, has been identified in the wild. Security researchers report that this variant has been actively compromising internet-connected devices, particularly common SOHO routers, for at least a month. The botnet spreads by exploiting a series of unpatched vulnerabilities in devices from numerous vendors, including Alcatel, D-Link, Netgear, and Tenda. Evooo1Bot reportedly includes new stealth capabilities, making it more resilient and harder to detect than its predecessors. The emergence of this variant underscores the ongoing threat posed by insecure IoT devices and the continuous evolution of malware designed to exploit them.
Mirai is a malware family that primarily targets online consumer devices such as routers and IP cameras. It infects them by scanning for open Telnet ports and attempting to log in with a list of common default usernames and passwords. Once infected, the devices become part of a botnet, which is then used to launch powerful Distributed Denial of Service (DDoS) attacks.
The Evooo1Bot variant continues this core functionality but adds two key elements:
The attack chain for Evooo1Bot follows the classic Mirai pattern, with the addition of vulnerability exploitation.
T1595.002 - Active Scanning: Vulnerability Scanning: The botnet actively scans for vulnerable devices.T1110.001 - Brute Force: Password Guessing: The traditional Mirai method of trying default credentials.T1210 - Exploitation of Remote Services: The new addition of exploiting specific firmware vulnerabilities.T1498 - Network Denial of Service: The ultimate goal of the botnet is to launch DDoS attacks.The report specifically names routers from the following vendors as being targeted:
The primary impact of Mirai and its variants is the ability to launch massive DDoS attacks capable of taking major websites and online services offline. For the owners of the infected devices, the impact includes poor device performance, increased bandwidth usage, and the risk of their device being used in illegal activities. The continuous evolution of Mirai with new exploits and stealth features means that the pool of potential bots is constantly being refreshed, ensuring the longevity of this threat.
No specific Indicators of Compromise were provided in the source articles.
For network administrators and home users, the following patterns could indicate an infection:
dvrHelper, xzy, etc.Keep router and IoT device firmware up-to-date to patch the vulnerabilities that Evooo1Bot exploits.
Mapped D3FEND Techniques:
Change default passwords on all devices to strong, unique passwords to defend against brute-force attacks.
Mapped D3FEND Techniques:
Isolate IoT devices on a separate network to prevent a compromise from spreading to more critical systems.
Mapped D3FEND Techniques:

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.