Evooo1Bot Linux Botnet Hijacks Routers as SOCKS5 Traffic Relay Nodes
A new modular, Mirai-based Linux botnet known as Evooo1Bot is targeting internet-connected routers, gateways, and other network devices, turning compromised systems into SOCKS5 traffic relay nodes.
In addition to proxying malicious traffic, Evooo1Bot can steal credentials, launch SSH brute-force attacks, provide attackers with interactive shell access, and conduct distributed denial-of-service (DDoS) attacks.
Security researchers say the Linux malware has been active since at least July, targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across multiple regions by exploiting known vulnerabilities.
.jpg)
Source: Fortinet
“The malware reuses the DDoS engine from the publicly leaked Mirai source code, but extends the original framework with a number of features, including encrypted C2 communications, an SSH brute force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers reported.
The latest Evooo1Bot build contains exploit modules targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations.
Fortinet researchers note that some of the embedded exploits are incorrectly implemented, meaning certain attacks may fail even when a targeted device is vulnerable.
After successfully exploiting a device, Evooo1Bot downloads one of 12 malware builds based on the system’s CPU architecture. The malware also clears Bash history to remove evidence of the intrusion.
The botnet uses encrypted command-and-control (C2) communications over port 443. Before activating, it performs extensive checks for debuggers, security software, sandboxes, virtual machines, containers, and honeypots.
Evooo1Bot establishes persistence through systemd, SysV init, shell profiles, and rc.local. It also creates a cron job that attempts to download the payload again every five minutes.

Source: Fortinet
An interactive shell gives Evooo1Bot operators direct control over infected systems. The malware also supports file transfers, allowing attackers to upload and download files.
Its credential-sniffing module monitors /proc/net/tcp and attempts to capture HTTP Basic Authentication credentials and cookie headers passing through the compromised device.
The SOCKS5 proxy module supports both direct listening and reverse relay modes. These capabilities allow attackers to conceal malicious traffic, bypass geographic restrictions, and access internal networks through compromised routers or gateways.
Fortinet says proxy sessions operate independently, allowing multiple connections to remain active simultaneously. If the botnet expands, its operators could potentially monetize infected devices through residential proxy services.
The SSH scanner uses 150 username-and-password combinations associated with enterprise accounts. After a successful login, it performs additional checks designed to identify and avoid honeypots.
Evooo1Bot also includes the Mirai-derived DDoS engine, which supports 16 flooding techniques. These include UDP, DNS, SYN, ACK, GRE, fragmented TCP, and HTTP floods with customizable requests.
To protect routers and IoT devices from Evooo1Bot and similar Linux botnet malware, install the latest firmware updates, replace default administrator credentials, disable unnecessary remote administration interfaces, and retire devices that no longer receive security support from their manufacturers.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




