<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Linux Malware on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/linux-malware/</link><description>Recent content in Linux Malware on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 17 Aug 2026 13:15:09 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/linux-malware/index.xml" rel="self" type="application/rss+xml"/><item><title>Evooo1Bot Turns Home Routers Into Rented Proxies With a Bug From 2007</title><link>https://hackingpassion.com/evooo1bot-router-botnet/</link><pubDate>Mon, 17 Aug 2026 13:15:09 +0200</pubDate><guid>https://hackingpassion.com/evooo1bot-router-botnet/</guid><description>&lt;h1 id="evooo1bot-turns-home-routers-into-rented-proxies-and-reads-the-traffic-passing-through">Evooo1Bot Turns Home Routers Into Rented Proxies and Reads the Traffic Passing Through&lt;/h1>
&lt;p>A botnet is breaking into home routers with a bug from &lt;strong>2007&lt;/strong>. &lt;strong>Ten known holes&lt;/strong>, and a list of &lt;strong>150 common logins&lt;/strong>. Nobody in the house clicked on anything. The internet still works fine.&lt;/p>
&lt;p>The bug from 2007 is a command injection in a phone system management tool. Send it a few extra characters where it expects a hostname, and it runs whatever was put there. It was published on &lt;strong>September 18, 2007&lt;/strong>. It scores &lt;strong>9.8&lt;/strong>. CISA still lists it as actively exploited, nineteen years later.&lt;/p></description></item></channel></rss>