Evooo1Bot: The Mirai Successor That Turns Your Router Into a SOCKS Proxy
There's a new botnet prowling the internet, and unlike its Mirai ancestors that just wanted to DDoS your favorite CDN into a brownout, Evooo1Bot is playing a longer game. Discovered back in July by FortiGuard Labs researcher Cara Lin, this modular Linux-based malware doesn't just chew up bandwidth — it quietly turns compromised routers and gateway devices into SOCKS5 relay nodes that can be chained into proxy networks for all sorts of downstream purposes.
What makes Evooo1Bot particularly interesting to folks who actually maintain edge devices is the breadth of its exploit arsenal. Fortinet's telemetry showed it hammering through a dozen known CVEs across hardware from Alcatel, NETGEAR, Tenda, D-Link, Mitsubishi Electric, and Telesquare — spanning vulnerabilities as old as CVE-2007-3010 (Alcatel OmniPCX Enterprise) and as recent as CVE-2025-10123 (D-Link DIR-823X). That CVE-2007 entry is 19 years old and the router it affects has probably been gathering dust in a cabinet since before you were born. Yet here it is, still getting pwned because someone somewhere left it on the public internet with default credentials. The malware also pulls in encrypted C2 communications (AES-256-CTR and ChaCha20 layered with XOR), an SSH brute-force scanner with honeypot evasion, a credential sniffer for HTTP Basic Auth and cookies, and five simultaneous persistence mechanisms. It even checks architecture before downloading its payload binary — a small but telling detail that suggests the operators are serious about scale.
The real kicker for sysadmins is the SOCKS relay module, which supports both direct and reverse modes. A compromised home router or SOHO gateway becomes a stepping stone, a traffic relay, a credential-harvesting platform, and a persistent backdoor — all from one infection. Most Mirai clones just add bots to a DDoS army. Evooo1Bot turns your gateway into infrastruct

Sources
- New Evooo1Bot Linux botnet turns routers into traffic relay nodes — BleepingComputer
- Multi-Functional Linux Botnet "Evooo1Bot" — FortiGuard Labs
- New Mirai-Based Linux Botnet 'Evooo1Bot' Turns Victims Into Proxies — Infosecurity Magazine
- Multi-Functional Linux Botnet "Evooo1Bot" — daily.dev / FortiGuard Threat Research
Comments
Post a Comment