Plan
active
Evooo1Bot Mirai-Derived Botnet Proxies Edge Devices via Known Vulns
- Engineer — Plan: Mirai-derived malware is actively targeting internet-facing Linux edge devices using known vulnerabilities to establish SOCKS5 proxy infrastructure; audit your exposed edge device inventory for signs of compromise, ensure firmware/OS patches are current on routers, VPN appliances, and similar gear, and block unauthorized outbound SOCKS5 traffic at the perimeter.
- SOC/IR — Plan: No specific IOCs are published yet, but the Mirai lineage gives detection footing — tune existing Mirai behavioral signatures and add rules hunting for anomalous SOCKS5 proxy establishment from edge device IP ranges; flag unusual outbound TCP 1080 or similar proxy-port connections from network appliance subnets.
- Leader — Learn: A new Mirai variant converting edge devices into proxy nodes is an emerging infrastructure threat worth tracking, but it presents no immediate vendor-breach, regulatory, or board-escalation trigger at this stage.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.