Evooo1Bot: The Mirai Successor That Turns Your Router Into a SOCKS Proxy

There's a new botnet prowling the internet, and unlike its Mirai ancestors that just wanted to DDoS your favorite CDN into a brownout, Evooo1Bot is playing a longer game. Discovered back in July by FortiGuard Labs researcher Cara Lin, this modular Linux-based malware doesn't just chew up bandwidth — it quietly turns compromised routers and gateway devices into SOCKS5 relay nodes that can be chained into proxy networks for all sorts of downstream purposes.

What makes Evooo1Bot particularly interesting to folks who actually maintain edge devices is the breadth of its exploit arsenal. Fortinet's telemetry showed it hammering through a dozen known CVEs across hardware from Alcatel, NETGEAR, Tenda, D-Link, Mitsubishi Electric, and Telesquare — spanning vulnerabilities as old as CVE-2007-3010 (Alcatel OmniPCX Enterprise) and as recent as CVE-2025-10123 (D-Link DIR-823X). That CVE-2007 entry is 19 years old and the router it affects has probably been gathering dust in a cabinet since before you were born. Yet here it is, still getting pwned because someone somewhere left it on the public internet with default credentials. The malware also pulls in encrypted C2 communications (AES-256-CTR and ChaCha20 layered with XOR), an SSH brute-force scanner with honeypot evasion, a credential sniffer for HTTP Basic Auth and cookies, and five simultaneous persistence mechanisms. It even checks architecture before downloading its payload binary — a small but telling detail that suggests the operators are serious about scale.

C2 Telemetry
Source image 1

The real kicker for sysadmins is the SOCKS relay module, which supports both direct and reverse modes. A compromised home router or SOHO gateway becomes a stepping stone, a traffic relay, a credential-harvesting platform, and a persistent backdoor — all from one infection. Most Mirai clones just add bots to a DDoS army. Evooo1Bot turns your gateway into infrastruct

Source article image
Source image 2
ure. The geographical spread shown in Fortinet's C2 telemetry covers a wide swath of internet-connected regions, and with active exploitation of at least ten CVEs, the attack surface is far from shrinking. The practical takeaway: if you have anything with a Linux firmware running on the public internet that hasn't been patched since 2019, it's probably already part of someone's proxy network. And probably won't be the last.

Sources

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door