Evooo1Bot Botnet Hijacks Devices Into SOCKS5 Proxies — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Fortinet FortiGuard Labs flagged Evooo1Bot, a previously undocumented Linux botnet that derives its core functionality from the publicly leaked Mirai source code and has been active in the wild since July 2026.
- The botnet exploits at least 10 known CVEs against routers, IP cameras, firewalls, and other edge devices — including flaws in Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link products — then loads a shell script that fetches a binary matched to the device CPU architecture and clears Bash history to cover its tracks.
- Evooo1Bot's post-exploitation toolkit includes an SSH brute-force scanner, a credential sniffer for HTTP Basic Auth and Cookie headers, DDoS attacks over DNS/TCP/UDP, and an HTTP exploit dispatcher targeting eight additional flaws in Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, PHP, D-Link, and Kubernetes.
- The malware checks for analysis tools, sandboxes, and virtual environments before establishing encrypted C2 communications on port 443 to blend in with expected HTTPS traffic at the network perimeter.
- Its SOCKS5 proxy module transforms infected hosts into network relays, letting attackers disguise malicious traffic with victim IPs, bypass geographic restrictions, and pivot into internal networks through already-compromised machines.
- Fortinet warned that at scale, the same capability could let operators build a distributed proxy infrastructure for anonymous traffic forwarding or monetization through residential and enterprise proxy services.
Why it matters: By converting each compromised edge device into a SOCKS5 proxy, attackers gain a distributed pool of legitimate residential and enterprise IPs to disguise malicious activity, bypass geo-restrictions, and pivot into internal networks — potentially selling the proxy network as a service, which raises the financial value of every infected host well beyond traditional DDoS-for-hire botnet use.
Ask SkimNews




