home.social

#chacha20 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chacha20, aggregated by home.social.

  1. New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies

    A sophisticated Linux botnet named Evooo1Bot has been actively targeting internet-facing devices since July 2026, exploiting multiple vulnerabilities in edge devices across diverse regions. Built on the leaked Mirai source code, this modular botnet features significantly enhanced capabilities including encrypted command-and-control communications, SSH brute-force scanning, and a reverse SOCKS relay module that transforms compromised devices into persistent proxies. The malware employs multiple encryption layers using AES-256-CTR, ChaCha20, and XOR-based obfuscation, alongside an integrated exploit arsenal targeting IoT devices, networking equipment, and enterprise applications. The SOCKS relay functionality enables attackers to conceal their origin, pivot into internal networks, and conduct follow-on operations through victim infrastructure, placing it well beyond conventional Mirai-derived malware in terms of technical sophistication.

    Pulse ID: 6a7f349eb2e90e5a682c7e6f
    Pulse Link: otx.alienvault.com/pulse/6a7f3
    Pulse Author: AlienVault
    Created: 2026-08-14 15:30:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #Edge #Encryption #InfoSec #IoT #Linux #Malware #Mirai #OTX #OpenThreatExchange #RAT #RCE #SSH #bot #botnet #AlienVault

  2. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault