TechNewsReel
Live

Evooo1Bot Botnet Turns Linux Edge Devices Into Stealthy SOCKS5 Proxies

Researchers discover a modular Mirai-based malware targeting IoT hardware to mask malicious traffic and steal credentials.

TechNewsReel Newsroom · August 17, 2026

Cybersecurity researchers at Fortinet have identified Evooo1Bot, a modular Linux botnet that transforms internet-facing edge devices into SOCKS5 proxies. The malware targets routers and IoT hardware to create a distributed network for masking malicious activity and bypassing geographic restrictions.

According to Fortinet, the botnet targets a wide array of hardware from brands including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. To ensure compatibility across diverse hardware, the attackers deploy 12 different builds tailored to the host's specific CPU architecture. Once a device is compromised, the malware establishes encrypted communication with its command-and-control (C2) server.

A Modular Evolution of Mirai

While Evooo1Bot inherits its DDoS engine from the leaked Mirai source code—supporting 16 different flood methods such as UDP, DNS, SYN, ACK, GRE, and HTTP floods—it extends the original framework with more sophisticated tools. Fortinet researchers noted that the malware adds an integrated arsenal of exploits targeting known vulnerabilities, alongside an SSH scanner that utilizes over 150 username and password combinations for brute-forcing.

Beyond network attacks, the botnet includes a credential sniffer that monitors '/proc/net/tcp' to capture HTTP authentication data and cookies. To ensure it remains active on the infected host, Evooo1Bot employs multiple persistence mechanisms, including systemd, SysV init, shell profiles, rc.local, and cron jobs.

The Shift Toward Stealth

The most significant addition to the Mirai lineage is the SOCKS5 module. This allows the botnet to operate in both direct listening and reverse relay modes, effectively turning a home or corporate router into a transit point for other attackers. By routing traffic through these residential edge devices, threat actors can hide their true origin and make malicious requests appear as legitimate traffic from a trusted consumer ISP.

This capability shifts the botnet's utility from simple disruption to long-term stealth and reconnaissance. The ability to pivot into internal networks via these proxies increases the risk for organizations that rely on edge devices with outdated firmware or default credentials.

Future Outlook

Security experts are now monitoring the scale of the Evooo1Bot deployment. Because residential proxy services can be monetized, there is a strong financial incentive for the operators to expand the botnet's footprint. Users of the affected brands are encouraged to update their device firmware and disable unnecessary remote management interfaces to mitigate the risk of infection.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.