Evooo1Bot Turns Routers Into SOCKS5 Relay Nodes
A Mirai-based modular Linux botnet is converting compromised routers into SOCKS5 relay nodes — the same ORB infrastructure pattern, repackaged again.

A new Mirai-based botnet called Evooo1Bot is doing what Mirai variants have been doing since 2016 in one respect, and something slightly more interesting in another. BleepingComputer reported Friday that Evooo1Bot targets internet-facing gateway devices — home routers, small-business edge hardware, the usual attack surface — and converts them into SOCKS5 traffic relay nodes. Not DDoS cannon nodes. Proxy relay nodes.
That’s the distinguishing characteristic. The classic Mirai use case was volumetric: compromise enough bandwidth-rich edge devices, point them all at a target simultaneously, and knock it offline. What Evooo1Bot’s operators want from the devices they compromise is something more durable — a dispersed layer of residential and commercial IP addresses to route traffic through, making that traffic look like it originates from somewhere legitimate. The same infrastructure pattern threat-intelligence teams have been calling ORB networks, operational relay boxes, anonymization layers, and a half-dozen other names depending on which attribution cluster is using it this week.
The infrastructure play
The mechanics here are not novel. UAT-7810’s “Longleash” ORB network — covered in July — used compromised Ruckus and ASUS gear for exactly this: residential IP transit to evade geo-restriction and reputation blocklists. The FBI’s POPA botnet takedown hit the same structural pattern in a commercially operated version of the relay service. The appeal is straightforward. Data-center IP ranges are on every blocklist. A residential IP from a router in Minneapolis, a gateway in São Paulo, and a home network in Osaka — those are harder to flag and harder to attribute.
What Evooo1Bot adds to that structural approach is the Mirai codebase running on Linux gateway firmware — a delivery chain that has proven reliable across ten years of evolution precisely because the underlying attack surface keeps expanding rather than contracting. The “modular” characterization in BleepingComputer’s reporting suggests the relay function is one component rather than the whole payload, though specifics on additional modules weren’t available at time of writing. BleepingComputer’s reporting is ongoing; more technical detail, IoCs, and affected model lists are expected to follow.
Two days ago, a different Mirai variant surfaced with encrypted C2 and a credential sniffer. These are separate campaigns running on the same foundational codebase — which is the relevant observation. Mirai leaked in 2016 and became infrastructure commons. Every threat actor with a use case for compromised edge devices now builds from that codebase or from derivatives of it. The variants multiply; the underlying attack surface doesn’t get addressed.
What this means for the devices involved
This morning, three critical vulnerabilities in OpenWrt’s LuCI management interface reached public disclosure — two rated CVSS 9.9. OpenWrt runs on a substantial share of the consumer and small-business router hardware that botnets like Evooo1Bot target. The timing is coincidental; the overlapping attack surface is not.
The practical picture: gateway devices are targeted because they’re persistent, network-adjacent, and largely unmonitored. The Tenda router backdoor disclosed in July remains unpatched months after disclosure. Firmware updates that do exist often require manual action nobody takes. And unlike endpoints, routers don’t generate EDR telemetry — if a compromised router is proxying traffic, the detection event most commonly shows up in downstream anomaly analysis rather than at the device itself.
The response to Evooo1Bot is the same response to the Mirai variant from Tuesday and the one before that: update firmware on gateway devices, disable remote management interfaces exposed to the public internet, segment networks so IoT and edge hardware isn’t sitting adjacent to anything sensitive, and baseline outbound traffic volumes on devices where “predictable” is actually achievable. None of this is new. The fact that it keeps being relevant says something about which side of this problem has consistent institutional support.
For current IoCs and technical indicators, follow BleepingComputer’s reporting and vendor advisories as they publish.
Found this useful? Share it.


