{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ssh-brute-force/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["botnet","linux","ddos","ssh-brute-force","proxy"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eEvooo1Bot is a newly analyzed modular Linux-based botnet identified by FortiGuard Labs. The threat actor leverages this malware to compromise internet-facing devices, converting them into active nodes within a botnet infrastructure. The botnet is notable for its multi-functional design, which supports a variety of malicious activities including distributed denial-of-service (DDoS) attacks, automated brute-force attempts against SSH services, the exploitation of known vulnerabilities to achieve initial access, and the utilization of infected hosts as SOCKS proxy relays to mask and redirect malicious traffic. This botnet targets a broad range of Linux-based devices, emphasizing the need for robust hardening of perimeter-facing services and strong credential management for administrative interfaces.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful compromise by Evooo1Bot results in the loss of device integrity, the potential for unauthorized network transit via SOCKS proxying, and the use of the device as a participant in wider DDoS attacks. The scope of impact includes potential service disruption, unauthorized access to internal resources, and increased risk of follow-on attacks originating from the local network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should focus on identifying unauthorized administrative access attempts and anomalous network traffic associated with SOCKS proxies.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for repeated failed SSH login attempts from diverse external IP addresses.\u003c/li\u003e\n\u003cli\u003eBaseline network traffic for high volumes of outbound connections on common proxy ports.\u003c/li\u003e\n\u003cli\u003eAudit internet-facing devices to ensure that all services are patched against known remote code execution vulnerabilities.\u003c/li\u003e\n\u003cli\u003eRestrict inbound SSH access to required management jump hosts or use multi-factor authentication for all remote access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T14:22:04Z","date_published":"2026-08-13T14:22:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-evooo1bot-linux-botnet/","summary":"Evooo1Bot is a modular Linux-based botnet that targets internet-facing devices to perform DDoS attacks, SSH brute-forcing, vulnerability exploitation, and SOCKS proxy relay operations.","title":"Evooo1Bot Modular Linux Botnet","url":"https://feed.craftedsignal.io/briefs/2026-08-evooo1bot-linux-botnet/"}],"language":"en","title":"CraftedSignal Threat Feed - Ssh-Brute-Force","version":"https://jsonfeed.org/version/1.1"}