Evooo1Bot Botnet Turns Hacked Devices Into SOCKS5 Proxies

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Fortinet FortiGuard Labs identified Evooo1Bot as a new Linux botnet family that reuses Mirai's DDoS engine while adding encrypted C2, an SSH brute-force scanner, a SOCKS relay, a credential sniffer, and an integrated exploit arsenal.
- Evooo1Bot has been active in the wild since July 2026, weaponizing 10 known CVEs against Alcatel, NETGEAR, Tenda, Mitsubishi, Telesquare, and D-Link devices to deliver a loader script ("wget.sh") from 91.92.40[.]118 that then erases Bash history.
- The botnet binary checks for analysis tools, sandboxes, and virtual machines before opening encrypted C2 communications on TCP port 443 to camouflage itself inside expected HTTPS traffic.
- Operators can issue commands for persistence, binary updates, file transfer, interactive shells, SSH brute-forcing, DNS/TCP/UDP DDoS, and HTTP Basic Authorization and Cookie header interception, plus an exploit module targeting eight more flaws in Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, PHP, D-Link, and Kubernetes.
- The SOCKS5 proxy module converts infected edge devices into relays that can disguise malicious traffic, bypass geo-restrictions, or pivot into internal networks, and Fortinet warned a large botnet could monetize the same capability through residential and enterprise proxy services.
Why it matters: Evooo1Bot turns commodity edge devices into stealthy SOCKS5 relays, not just DDoS drones — meaning every infection becomes a paid anonymization node for the operator. With 18 known CVEs in its toolkit spanning consumer routers, IP cameras, and enterprise software, unpatched devices face a dual risk of credential theft and traffic laundering within a single compromise.
Ask SkimNews




