New Evooo1Bot Linux botnet turns routers into traffic relay nodes

As cybersecurity threats continue to evolve, a new and potent strain of malware has emerged on the scene. The Evooo1Bot Linux botnet, based on Mirai code, is turning internet-facing gateway devices into SOCKS5 traffic relay nodes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems.

The malware’s capabilities extend far beyond simply turning devices into proxy nodes. It also includes credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks. Since at least July, Evooo1Bot has been targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions by exploiting known vulnerabilities.

One of the most striking aspects of Evooo1Bot is its modular design, which allows it to adapt to different environments and evade detection. According to Fortinet researchers, the malware reuses the DDoS engine from Mirai source code but extends the original framework with numerous capabilities, including encrypted command-and-control (C2) communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities.

Newer builds of Evooo1Bot include a separate vulnerability-exploitation module that targets Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation.

When leveraging an exploit successfully, a script downloads one of the 12 available malware builds that match the host’s CPU architecture, then clears Bash history to wipe traces of the attack. Evooo1Bot uses encrypted C2 communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it launches on the infected device.

The malware establishes persistence through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes. An interactive shell gives operators direct control over compromised systems, while file-transfer commands support uploads and downloads. The credential sniffer module monitors ‘/proc/net/tcp’ and attempts to capture HTTP Basic Authentication and Cookie headers.

The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic or access networks through compromised systems. Fortinet warns that proxying sessions run independently, and multiple can be opened simultaneously, enabling monetization through residential proxy services if the botnet grows large enough.

In light of this threat, it’s essential for users to take proactive steps to protect their IoT devices. This includes keeping firmware updated, replacing default admin credentials, turning off remote access panels, and replacing devices when vendors no longer provide support for them. As the Blue Report 2026 highlights, once attackers have valid credentials, only 37% of their actions are blocked – emphasizing the importance of robust defenses beyond initial prevention measures.


Source: Bleeping Computer — 2026-08-15