Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies
Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.

Active since July. Confirmed by Fortinet researchers. A Mirai-based modular Linux botnet — Evooo1Bot — is compromising internet-facing gateway devices and converting them into SOCKS5 traffic relay nodes.
Source: BleepingComputer — New Evooo1Bot Linux botnet turns routers into traffic relay nodes.
Target range
Confirmed exposed targets: gateway devices from Alcatel, NETGEAR, Tenda, TP-Link, D-Link, Telesquare, and Zyxel. Later variants extended scope to Hikvision cameras, D-Link NAS devices, and server-side software including Atlassian Confluence, WSO2 products, and Kubernetes ingress-nginx controllers.
Target list is expanding — unconfirmed whether additional products are in scope.
How it lands
Exploitation module targeting known vulnerabilities. Successful compromise triggers download of one of twelve architecture-matched payload builds. Bash history cleared post-infection. Specific CVEs exploited: not disclosed in Fortinet’s published analysis.
What it does
Primary capability: SOCKS5 proxy. Supports direct listening and reverse-relay modes with multiple simultaneous sessions. The relay function routes attacker traffic through the victim device, masking origin — useful for credential stuffing, exfiltration staging, and evading geographic blocks or rate limits.
Additional modules confirmed:
- Encrypted C2 over port 443
- SSH brute-force using 150 credential pairs
- Credential sniffing targeting HTTP Basic Auth and Cookie headers
- 16 DDoS flood methods: UDP, DNS, SYN, ACK, GRE, HTTP variants
- Interactive shell with file transfer
- Anti-analysis checks: debugger detection, security tool detection, sandbox and VM fingerprinting
Persistence: systemd, SysV init, shell profiles, rc.local, and cron. The cron entry re-downloads the implant every five minutes if removed.
Exposure and mitigation
Firmware current: required. Default credentials in use: change them. Remote management exposed to internet: disable. Devices beyond vendor support: retire, not patch.
No CISA KEV additions for this activity as of this writing — unconfirmed, treat accordingly.
Related: FBI, Europol Dismantle NetNut/POPA Botnet Proxy Network · Unit 42 Tracks TuxBot v3 IoT Botnet · Linux brcmfmac WiFi Heap Overflow
Found this useful? Share it.


