<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux-Botnet on CuraSec</title><link>https://curasec.metacog.co.kr/tags/linux-botnet/</link><description>Recent content in Linux-Botnet on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 17 Aug 2026 11:37:07 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/linux-botnet/index.xml" rel="self" type="application/rss+xml"/><item><title>Evooo1Bot Mirai-Derived Botnet Proxies Edge Devices via Known Vulns</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-evooo1bot-linux-botnet-exploits-known-flaws-to-turn-edge-dev/</link><pubDate>Mon, 17 Aug 2026 11:37:07 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-evooo1bot-linux-botnet-exploits-known-flaws-to-turn-edge-dev/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Mirai-derived malware is actively targeting internet-facing Linux edge devices using known vulnerabilities to establish SOCKS5 proxy infrastructure; audit your exposed edge device inventory for signs of compromise, ensure firmware/OS patches are current on routers, VPN appliances, and similar gear, and block unauthorized outbound SOCKS5 traffic at the perimeter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No specific IOCs are published yet, but the Mirai lineage gives detection footing — tune existing Mirai behavioral signatures and add rules hunting for anomalous SOCKS5 proxy establishment from edge device IP ranges; flag unusual outbound TCP 1080 or similar proxy-port connections from network appliance subnets.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A new Mirai variant converting edge devices into proxy nodes is an emerging infrastructure threat worth tracking, but it presents no immediate vendor-breach, regulatory, or board-escalation trigger at this stage.&lt;/li>
&lt;/ul></description></item></channel></rss>