MalwareEvooo1Bot Turns Linux Gateways into SOCKS5 Relays for Attacks and Credential Theft
Evooo1Bot is a Linux botnet exploiting exposed gateways to create SOCKS5 relays for attacks and credential theft, with persistence and DDoS capabilities.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
MalwareEvooo1Bot is a Linux botnet exploiting exposed gateways to create SOCKS5 relays for attacks and credential theft, with persistence and DDoS capabilities.
MalwareOn August 14, 2026, Jamf Threat Labs reported AmnesiaStealer, a new Rust-based infostealer designed to target macOS users. The observed distribution
APTU.S. government launches program for private cybersecurity firms to engage in offensive operations against foreign cybercrime, under strict federal control.
APTOn August 13, 2026, some users reported on Reddit that they had received new Apple Threat Notifications —alerts Apple sends to iPhone owners when it
RansomwareAkira ransomware affiliate disabled EDR and antivirus in Safe Mode after accessing a VPN without MFA, but failed to encrypt files, highlighting security vulnerabilities.
MalwareDiscover how Android users are targeted by SpyNote and WindRelay malware in a scam combining fraudulent loans and NFC relay for contactless fraud.
APTCheck Point Research attributes a cyber-espionage campaign targeting defense and aerospace companies in France, Germany, Brazil, and India to the Lazarus
APTLazarus group exploits Windows zero-day in fake job campaign targeting defense. Microsoft patched CVE-2026-68820; update now.
RansomwareDeadLock ransomware uses Polygon blockchain for decentralized data leaks and chat, hindering stopping efforts with 96 victims and advanced encryption.
RansomwareCISA confirms ransomware exploitation of SharePoint CVE-2026-45659 vulnerability. Patch servers and enable AMSI to prevent code execution and network breaches.
APTGenians attributes the preparation of infrastructure for running artificial intelligence tools offline to Kimsuky, a North Korean unit subordinate to the
APTThe Coruna and DarkSword iOS exploit chains, initially associated with state-sponsored actors and mercenary surveillance vendors, are now spreading among