New Evooo1Bot Linux botnet turns routers into traffic relay nodes
August 15, 2026 · BleepingComputer · Severity: HIGH
Evooo1Bot is a newly discovered Linux botnet built on the Mirai source code, specifically designed to compromise internet-facing gateway devices such as routers and modems. Once infected, these devices are transformed into SOCKS5 traffic relay nodes, effectively allowing threat actors to route malicious traffic through home and small-office networks. This functionality enables anonymity for the operators and can be abused for various cybercriminal activities, including credential stuffing, payment fraud, and other proxy-based attacks. The botnet's modular architecture is a notable evolution from traditional Mirai variants, which primarily focused on distributed denial-of-service attacks. By incorporating SOCKS5 relay capabilities, Evooo1Bot expands the utility of compromised routers, turning them into a resilient and distributed proxy infrastructure. Security researchers highlight that the targeting of edge devices is particularly dangerous, as these often have weak default credentials and receive infrequent firmware updates, making them attractive and easily exploitable targets for large-scale botnet operations.
Key Takeaways
- Evooo1Bot is a new Mirai-based Linux botnet targeting internet-facing gateway devices.
- The malware turns compromised routers into SOCKS5 proxies for traffic relay.
- Its modular design suggests evolving capabilities beyond initial DDoS functions.