A new and highly sophisticated botnet, dubbed “Evooo1Bot,” has been discovered compromising Linux-based edge devices worldwide. This botnet exploits known vulnerabilities in various software applications, turning compromised machines into SOCKS5 proxies that can be controlled remotely by attackers. The implications are far-reaching, with potentially millions of devices at risk.
At the heart of this issue is the fact that many edge devices, such as network-attached storage (NAS) systems and IoT appliances, run outdated or unpatched versions of popular software packages like OpenSSL and OpenSSH. These vulnerabilities allow Evooo1Bot to gain unauthorized access and establish a persistent foothold on infected devices.
Once inside, the malware injects itself into system processes, creating a SOCKS5 proxy that enables attackers to tunnel network traffic through compromised devices. This allows them to mask their own IP addresses and carry out malicious activities, including data exfiltration and DDoS attacks. The botnet’s architecture is built around a command-and-control (C2) infrastructure, with infected devices reporting back to central servers for instructions.
The impact of Evooo1Bot extends far beyond mere network compromise; it creates a complex web of interconnected vulnerabilities that can be exploited further by other threat actors. This “identity exposure” enables attackers to map privilege escalation routes and sever breach pathways at strategic chokepoints, effectively creating multiple avenues for future attacks.
As the discovery of Evooo1Bot highlights, many edge devices remain woefully unpatched or misconfigured, leaving their users exposed to a range of cyber threats. The fact that known vulnerabilities are being exploited on this scale underscores the need for greater vigilance and awareness among both device manufacturers and end-users.
In light of this threat, it’s essential for all Linux-based system administrators and owners to review their networks’ vulnerability profiles and apply necessary patches to affected software packages. Regularly updating OpenSSL, OpenSSH, and other applications is crucial in preventing similar attacks from succeeding in the future. By taking proactive steps to secure their edge devices, individuals can mitigate the risk of compromise and prevent potentially catastrophic consequences.
Source: The Hacker News — 2026-08-17