Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies

Fortinet researchers track Evooo1Bot, a Mirai-based modular Linux botnet hijacking routers as SOCKS5 relays with DDoS and credential-sniffing capability.

Evooo1Bot Botnet Hijacks Routers as SOCKS5 Proxies
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Active since July. Confirmed by Fortinet researchers. A Mirai-based modular Linux botnet — Evooo1Bot — is compromising internet-facing gateway devices and converting them into SOCKS5 traffic relay nodes.

Source: BleepingComputer — New Evooo1Bot Linux botnet turns routers into traffic relay nodes.

Target range

Confirmed exposed targets: gateway devices from Alcatel, NETGEAR, Tenda, TP-Link, D-Link, Telesquare, and Zyxel. Later variants extended scope to Hikvision cameras, D-Link NAS devices, and server-side software including Atlassian Confluence, WSO2 products, and Kubernetes ingress-nginx controllers.

Target list is expanding — unconfirmed whether additional products are in scope.

How it lands

Exploitation module targeting known vulnerabilities. Successful compromise triggers download of one of twelve architecture-matched payload builds. Bash history cleared post-infection. Specific CVEs exploited: not disclosed in Fortinet’s published analysis.

What it does

Primary capability: SOCKS5 proxy. Supports direct listening and reverse-relay modes with multiple simultaneous sessions. The relay function routes attacker traffic through the victim device, masking origin — useful for credential stuffing, exfiltration staging, and evading geographic blocks or rate limits.

Additional modules confirmed:

  • Encrypted C2 over port 443
  • SSH brute-force using 150 credential pairs
  • Credential sniffing targeting HTTP Basic Auth and Cookie headers
  • 16 DDoS flood methods: UDP, DNS, SYN, ACK, GRE, HTTP variants
  • Interactive shell with file transfer
  • Anti-analysis checks: debugger detection, security tool detection, sandbox and VM fingerprinting

Persistence: systemd, SysV init, shell profiles, rc.local, and cron. The cron entry re-downloads the implant every five minutes if removed.

Exposure and mitigation

Firmware current: required. Default credentials in use: change them. Remote management exposed to internet: disable. Devices beyond vendor support: retire, not patch.

No CISA KEV additions for this activity as of this writing — unconfirmed, treat accordingly.

Related: FBI, Europol Dismantle NetNut/POPA Botnet Proxy Network · Unit 42 Tracks TuxBot v3 IoT Botnet · Linux brcmfmac WiFi Heap Overflow

Found this useful? Share it.