Linux Evooo1Bot botnet turns routers into stealth proxies

A new Mirai-derived Linux botnet dubbed Evooo1Bot is hijacking internet-facing routers and edge devices, turning them into multi-purpose attack platforms that serve as SOCKS5 proxy nodes rather than mere DDoS cannons.[1][3][6] Researchers at FortiGuard Labs and other firms report that the malware’s operators are actively enrolling compromised hardware into infrastructure that supports distributed denial-of-service attacks, credential theft, and stealthy traffic relays.[1][2][5]

According to technical analyses, Evooo1Bot reuses the classic Mirai DDoS engine but embeds it in a modular framework that adds encrypted command-and-control, SSH brute-force scanning, credential-sniffing, and a flexible exploit arsenal.[1][2][5] Mirai itself is known for conscripting vulnerable IoT and edge devices into large botnets capable of high-volume UDP, TCP, DNS, and HTTP flooding attacks, and Evooo1Bot retains those capabilities while expanding the playbook far beyond denial-of-service.[10][11][15] FortiGuard’s report describes multiple persistence mechanisms, including use of system services and scheduled tasks, intended to keep the malware resident on lightly managed gateways and embedded Linux systems.[1][2]

The initial access phase blends aggressive scanning for exposed management interfaces with exploitation of known vulnerabilities in popular network and IoT products, including Hikvision cameras, Atlassian Confluence servers, Zyxel firewalls, TP-Link routers, D-Link NAS systems, and other edge hardware.[2][8][7] Public write-ups indicate that Evooo1Bot chains together exploits for roughly ten documented flaws across vendors, but they do not enumerate specific CVE identifiers or CVSS scores, leaving defenders to cross-reference their own asset inventories against current advisories and firmware releases.[2][7][8] Once a device is compromised, the bot can deploy modules that provide interactive shells and file transfer, giving operators broad control over systems that frequently sit at critical network choke points.[2][3][5]

What sets Evooo1Bot apart from many Mirai variants is its emphasis on SOCKS5 proxying, including a reverse relay mode that builds encrypted outbound tunnels from the victim to attacker-controlled infrastructure.[3][4][5] Reporting from multiple security teams suggests the botnet is being used to route malicious traffic through legitimate residential and corporate IP addresses, obscuring the true origin of attacks, bypassing IP-based geofencing, and providing covert paths into internal networks behind compromised gateways.[4][6][7] Combined with a credential-sniffing module that monitors HTTP Basic Authentication and cookie headers on passing traffic, the operation can both launder activity and harvest sensitive data flowing through these devices.[5][9]

The defender impact is significant because routers, industrial controllers, and other embedded Linux systems typically lack endpoint agents, have limited logging, and are rarely monitored as potential proxy infrastructure.[3][6][7] Analysts warn that organizations may first notice Evooo1Bot infections not through local alerts but when their addresses appear in upstream abuse reports or threat intelligence feeds as apparent sources of DDoS floods, credential-stuffing attempts, or lateral movement into other environments.[3][5][6] The use of encrypted C2 and nonstandard ports further complicates detection, making behavioral indicators—such as unexpected high-volume outbound connections, spikes in bandwidth consumption, or anomalous authentication traffic—critical for spotting compromised devices.[1][4][14]

Mitigating Evooo1Bot’s impact begins with treating routers, VPN appliances, and other edge systems as high-value assets: operators should inventory internet-facing devices, apply the latest vendor firmware updates, and close or restrict remote-management interfaces wherever possible.[2][3][7] Replacing default and weak credentials, enforcing strong authentication on SSH and web consoles, and segmenting edge hardware from sensitive internal networks can significantly reduce the botnet’s ability to brute-force logins and pivot beyond the perimeter.[3][5][15] Network teams are also urged to monitor for unusual outbound proxy-like traffic patterns and to work with ISPs or cloud providers on blocking known malicious destinations, recognizing that compromised gateways in this campaign are being weaponized not just for DDoS but as persistent, monetizable infrastructure for broader cyber operations.[3][4][6]

References

  1. Linux Botnet Evooo1Bot Expands Mirai Capabilities Beyond DDoS
  2. ИИ-кодер может запустить вредоносную команду из чистого …
  3. Evooo1Bot Linux Botnet: Detecting and Remediating Mirai-Variant …
  4. ‘Evooo1Bot’—Advanced Mirai-Derived Linux Botnet Targets Edge …
  5. Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
  6. Evooo1Bot Botnet Recruits Routers as SOCKS5 Relays
  7. Evooo1Bot Botnet Turns Routers Into Proxy Relays
  8. Evooo1Bot Uses Routers as Stealth Proxy Nodes · PlainSec
  9. Evooo1Bot Adds Stealth, Credential Theft and Proxy Capabilities to …
  10. What Is the Mirai Botnet? – Radware
  11. What is the Mirai Botnet? – Cloudflare
  12. ️ SOCKS proxy
  13. The Mirai Botnet – Threats and Mitigations

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply