Evooo1Bot Botnet Turns Linux Routers Into Stealthy Traffic Relays
A Mirai-derived malware transforms internet-facing gateway devices into SOCKS5 proxy nodes to mask attacker origins.
A new modular Linux botnet known as Evooo1Bot is targeting internet-facing gateway devices and routers to create a distributed network of traffic relays. The malware allows attackers to route malicious activity through legitimate home and business hardware, effectively masking the origin of their attacks.
Based on the Mirai source code, Evooo1Bot reuses the established DDoS engine but introduces several new modular capabilities. Most notably, the malware transforms infected devices into SOCKS5 traffic relay nodes. This functionality enables operators to use compromised IoT devices as a proxy network, allowing them to bypass IP-based security filters and geo-blocking by making malicious traffic appear as if it originates from a residential or corporate gateway.
The Evolution of Mirai
This development marks a continuation of a broader trend in cybercrime where Mirai-derived malware evolves from simple tools for Distributed Denial of Service (DDoS) attacks into multi-functional platforms. Rather than simply flooding a target with traffic, modern botnets are increasingly designed for persistence and stealth.
To maintain and expand its footprint, Evooo1Bot employs a suite of aggressive propagation and surveillance tools. The malware includes an SSH brute-force scanner used to compromise new devices and a credential sniffer designed to harvest sensitive information. Furthermore, the botnet utilizes encrypted command-and-control (C2) communications to avoid detection by network security monitoring tools.
Implications for Network Security
The shift toward traffic relay functionality significantly increases the stealth of cyberattacks and complicates the process of attribution. When an attack is routed through a SOCKS5 proxy on a compromised router, security teams see the IP address of an innocent home or business user rather than the actual attacker's infrastructure.
Because the botnet specifically targets critical gateway devices, the risks extend beyond simple proxying. By compromising the router—the primary entry and exit point for a network—the malware can potentially provide a persistent foothold for attackers. This turns common household and office hardware into foundational infrastructure for larger, more complex criminal operations, potentially allowing for the interception of network traffic.
What to Watch
Security professionals are advised to monitor for unusual SSH login attempts and unexpected outbound traffic on gateway devices. While the core capabilities of Evooo1Bot are confirmed, the full scale of its current infection rate and the specific identities of the operators remain unconfirmed. As the botnet continues to evolve, the industry will be watching for further modular updates that could expand its ability to pivot from the gateway into deeper internal network segments.