Infosecurity

Evooo1Bot: New Mirai-Based Linux Botnet Turns Hacked Devices Into Proxies

Published

on

Evooo1Bot: A New Twist on an Old Threat

Security researchers have spotted a fresh Linux botnet that borrows its core from the infamous Mirai malware — but adds some serious upgrades. Dubbed Evooo1Bot by Fortinet’s FortiGuard Labs, this modular threat is actively exploiting a wide range of vulnerabilities in routers and edge devices. The goal? Not just DDoS attacks, but turning victims into covert proxies.

The botnet gets its name from the hardcoded string “evooo1” found in every binary. Analyst Yi Ping (Cara) Lin published the technical breakdown on August 13, after observing a string of exploit attempts tied to a single loader URL: 91.92.40[.]118/wget.sh.

That URL was the common thread linking attacks against at least ten distinct CVEs, spanning vendors like Alcatel, NETGEAR, Tenda, D-Link, and Mitsubishi Electric.

Targets: Old and New Vulnerabilities

Evooo1Bot isn’t picky. It goes after legacy flaws that have been public for years, alongside more recent disclosures. Some of the key CVEs in its arsenal:

  • CVE-2007-3010 — Alcatel OmniPCX Enterprise RCE
  • CVE-2016-6277 — NETGEAR multiple routers RCE
  • CVE-2018-14558 — Tenda AC7, AC9, AC10 command injection
  • CVE-2020-10987 — Tenda AC15 RCE
  • CVE-2021-46422 — Telesquare SDT-CW3B1 command injection
  • CVE-2022-37055 — D-Link routers buffer overflow
  • CVE-2024-29269 — Telesquare TLR-2005KSH command injection
  • CVE-2025-10123 — D-Link DIR-823X command injection
  • CVE-2025-55583 — D-Link DIR-868L B1 command injection

That mix of old and new is a deliberate strategy. Many of these devices are end-of-life, meaning vendors won’t patch them. And plenty of still-supported gear never gets updated by users anyway.

More Than Just DDoS

Mirai’s original claim to fame was massive distributed denial-of-service attacks, powered by armies of compromised IoT cameras and routers. The source code leaked in September 2016, after creator Paras Jha and his co-conspirators released it to muddy the waters as the FBI closed in. That leak spawned a thousand copycats.

Evooo1Bot follows that lineage, but it’s not content to just flood targets with traffic. The malware includes a 28-command remote administration interface, encrypted C2 communications, and an SSH brute-force scanner. It also packs a credential sniffer and multiple layers of obfuscation using AES-256-CTR, ChaCha20, and XOR-based key derivation.

What really sets it apart, according to Lin, is the reverse SOCKS relay module. That feature turns a compromised device into a persistent proxy. An attacker can route traffic through the victim’s machine, hiding their true origin and pivoting deeper into internal networks.

“These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware,” Lin wrote in her analysis.

How the Proxy Relay Works

The SOCKS relay is arguably the most operationally significant part of the botnet. Here’s why it matters:

  • Anonymity — Attackers route traffic through victim devices, making attribution much harder.
  • Pivoting — Once inside a network, they can move laterally to other systems.
  • Follow-on operations — The same proxy can be used for credential theft, data exfiltration, or further exploitation.

In other words, your router could be someone else’s getaway car.

Who’s Being Targeted?

Lin’s analysis suggests Evooo1Bot has been actively scanning for internet-facing devices since at least July 2026. The campaign appears to span multiple regions, with no single geographic focus. Any organization with exposed routers, switches, or IoT gear is a potential victim.

That’s a wide net. Small offices, home users, industrial control networks — all rely on edge devices that are often forgotten once installed.

How to Protect Yourself

There’s no single silver bullet, but basic hygiene goes a long way:

  • Patch everything — Apply firmware updates as soon as they’re available. For end-of-life devices, replace them.
  • Change default credentials — Mirai’s original trick was guessing weak passwords. Don’t give it a chance.
  • Disable remote management — If you don’t need admin access from the internet, turn it off.
  • Segment your network — Keep IoT devices on a separate VLAN so a compromise doesn’t spread.
  • Monitor for anomalies — Unexpected outbound connections from routers or cameras are a red flag.

For more on how these attacks unfold, check out our guide on Mirai botnet variants and IoT security. And if you’re wondering about the broader threat landscape, read about router vulnerabilities and how to fix them.

The Bottom Line

Evooo1Bot is a reminder that old code never dies — it just gets repurposed. Mirai’s leaked source has fueled a decade of malware, and this latest variant shows how far the genre has evolved. The DDoS engine is still there, but the proxy relay and encryption make it a far more dangerous tool.

If you have internet-facing devices, assume they’re being scanned right now. Patch what you can, replace what you can’t, and don’t rely on default settings to keep you safe.

Stay ahead of the threat. Learn more about botnet protection strategies to keep your network clean.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version