Mirai Variant 'Evooo1Bot' Exploits Unpatched Routers

New Stealthy Mirai Variant 'Evooo1Bot' Targets Common Routers

HIGH
August 15, 2026
5m read
MalwareIoT SecurityCyberattack

Related Entities

Organizations

AlcatelD-LinkNetgearTenda

Other

Mirai Evooo1Bot

Full Report

Executive Summary

A new variant of the notorious Mirai botnet malware, dubbed Evooo1Bot, has been identified in the wild. Security researchers report that this variant has been actively compromising internet-connected devices, particularly common SOHO routers, for at least a month. The botnet spreads by exploiting a series of unpatched vulnerabilities in devices from numerous vendors, including Alcatel, D-Link, Netgear, and Tenda. Evooo1Bot reportedly includes new stealth capabilities, making it more resilient and harder to detect than its predecessors. The emergence of this variant underscores the ongoing threat posed by insecure IoT devices and the continuous evolution of malware designed to exploit them.


Threat Overview

Mirai is a malware family that primarily targets online consumer devices such as routers and IP cameras. It infects them by scanning for open Telnet ports and attempting to log in with a list of common default usernames and passwords. Once infected, the devices become part of a botnet, which is then used to launch powerful Distributed Denial of Service (DDoS) attacks.

The Evooo1Bot variant continues this core functionality but adds two key elements:

  1. Exploitation of Specific Vulnerabilities: In addition to brute-forcing credentials, this variant actively exploits a series of known, unpatched software vulnerabilities in specific router models.
  2. Enhanced Stealth: The variant's code has been modified to include new features designed to evade detection and make removal from the infected device more difficult.

Technical Analysis

The attack chain for Evooo1Bot follows the classic Mirai pattern, with the addition of vulnerability exploitation.

  1. Scanning: The bot scans the internet for potential targets (routers) with open ports or known vulnerabilities.
  2. Infection: The bot attempts to compromise the target either by guessing default credentials or by using a built-in exploit for a specific vulnerability.
  3. Payload Delivery: Upon successful compromise, the bot downloads and executes the main malware payload.
  4. Persistence & C2: The malware establishes persistence, kills competing malware or legitimate services, and connects to a command-and-control (C2) server to await instructions.
  5. Attack: When instructed, the entire botnet of compromised devices floods a target with traffic, causing a DDoS attack.

MITRE ATT&CK TTPs

Affected Products

The report specifically names routers from the following vendors as being targeted:

  • Alcatel
  • D-Link
  • Netgear
  • Tenda

Impact Assessment

The primary impact of Mirai and its variants is the ability to launch massive DDoS attacks capable of taking major websites and online services offline. For the owners of the infected devices, the impact includes poor device performance, increased bandwidth usage, and the risk of their device being used in illegal activities. The continuous evolution of Mirai with new exploits and stealth features means that the pool of potential bots is constantly being refreshed, ensuring the longevity of this threat.

IOCs — Directly from Articles

No specific Indicators of Compromise were provided in the source articles.

Cyber Observables — Hunting Hints

For network administrators and home users, the following patterns could indicate an infection:

Type
network_traffic_pattern
Value
Large volume of outbound SYN, UDP, or HTTP floods
Description
This is the classic sign of a device participating in a DDoS attack.
Context
Firewall logs, Netflow analysis, ISP reports
Type
port
Value
23, 2323
Description
Mirai often scans for other devices on Telnet ports 23 and 2323. Outbound traffic on these ports from an IoT device is highly suspicious.
Context
Network monitoring tools
Type
process_name
Value
dvrHelper, xzy, etc.
Description
Mirai often uses common or random process names to disguise itself on the infected device.
Context
Device process list (if accessible)

Detection & Response

  • Network Monitoring: Monitor for unusual outbound traffic patterns from IoT devices. A device that is suddenly sending a large amount of traffic to a single destination is likely part of a DDoS attack.
  • Port Scanning: Scan your own network from an external source to identify any unexpectedly open ports on your router or other IoT devices.
  • Reboot and Patch: A simple reboot can sometimes remove non-persistent malware like some Mirai variants. However, the device will likely be reinfected quickly if the underlying vulnerability is not patched. The correct procedure is to reboot, then immediately log in and apply the latest firmware update.

Mitigation

  1. Update Firmware: Ensure all routers and IoT devices are running the latest firmware from the manufacturer. This is the most effective defense against exploit-based variants like Evooo1Bot. This is a core D3FEND Software Update (D3-SU).
  2. Use Strong, Unique Passwords: Change the default administrator password on all devices to something long and unique. Avoid using simple or common passwords. This aligns with MITRE Mitigation M1027 - Password Policies.
  3. Network Segmentation: Place IoT devices on a separate network segment or VLAN that has restricted access to the internet and to your primary network. This can limit their ability to scan for other victims and prevent them from being used to attack internal devices.

Timeline of Events

1
August 15, 2026
This article was published

MITRE ATT&CK Mitigations

Keep router and IoT device firmware up-to-date to patch the vulnerabilities that Evooo1Bot exploits.

Mapped D3FEND Techniques:

Change default passwords on all devices to strong, unique passwords to defend against brute-force attacks.

Mapped D3FEND Techniques:

Isolate IoT devices on a separate network to prevent a compromise from spreading to more critical systems.

Mapped D3FEND Techniques:

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

MiraiBotnetEvooo1BotIoTDDoSRouter

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.