New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new and highly versatile Linux botnet malware has been spotted in the wild, targeting internet-facing gateway devices and turning them into SOCKS5 traffic relay nodes. The malware, dubbed Evooo1Bot, is based on the Mirai framework but has added numerous capabilities that make it a significant threat to network security.

Evooo1Bot has been active since at least July of this year, with researchers at Fortinet discovering its presence in devices from several major manufacturers, including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The malware exploits known vulnerabilities in these devices to gain access and then uses a range of modules to turn them into proxy nodes, launch distributed denial-of-service (DDoS) attacks, steal credentials, and even conduct SSH brute-forcing.

One of the most concerning aspects of Evooo1Bot is its ability to use encrypted command-and-control (C2) communications over port 443. This makes it difficult for security tools to detect the malware’s presence on a network. Once inside, the malware performs extensive checks to ensure that it is running in a non-debugging environment and uses a range of persistence mechanisms to stay on the system.

Evooo1Bot also features an interactive shell that allows operators to directly control compromised systems, as well as file-transfer commands for uploading and downloading files. The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic or access networks through compromised systems.

The malware’s credential sniffer module monitors HTTP Basic Authentication and Cookie headers, while the SSH scanner module uses 150 username and password combinations for enterprise-oriented accounts. The DDoS module inherited from Mirai supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests.

The potential consequences of Evooo1Bot’s capabilities are significant. With its ability to turn devices into proxy nodes, attackers can conceal malicious traffic or access networks through compromised systems. The malware’s credential sniffer module also poses a significant threat, as it allows attackers to capture sensitive login information.

To defend against botnet malware like Evooo1Bot, users should take steps to secure their IoT devices. This includes keeping firmware updated, replacing default admin credentials, turning off remote access panels, and replacing devices when the vendor no longer provides support for them. Once attackers have valid credentials, prevention measures are significantly less effective.

By taking proactive steps to secure our networks and devices, we can reduce the risk of falling victim to malware like Evooo1Bot. As the threat landscape continues to evolve, it’s essential that we stay vigilant and take steps to protect ourselves from emerging threats like this one.


Source: Bleeping Computer — 2026-08-15