All incidents

Evooo1Bot Linux botnet hijacks edge devices as SOCKS5 proxies

malwareopenAug 14, 2026 — Aug 17, 2026
Evooo1Bot Linux botnet hijacks edge devices as SOCKS5 proxies

RESEARCHERS have identified a new Linux botnet dubbed Evooo1Bot that is compromising edge devices and converting them into SOCKS5 proxies for malicious traffic. The Hacker News first reported the activity in mid‑August 2026, noting that the malware builds on the Mirai codebase while adding several new capabilities.

According to analysis from Fortinet’s threat research team the botnet began scanning for vulnerable devices in July 2026 and targets known flaws in products from Alcatel, NETGEAR, D-Link and other vendors. Infosecurity Magazine notes that Evooo1Bot adds encrypted command‑and‑control channels, an SSH brute‑force scanner, credential sniffers and a reverse SOCKS relay to the Mirai foundation.

Unlike many Mirai variants that rely solely on telnet brute force, Evooo1Bot leverages existing CVEs and misconfigurations to gain initial access, then deploys a loader that contacts a central server to download the main payload. The malware’s reverse SOCKS component allows attackers to route traffic through compromised devices, effectively hiding the origin of spam, credential stuffing or other illicit activities.

Although no specific threat actor has been attributed to Evooo1Bot, the timing and tactics suggest a financially motivated operation seeking to monetise proxy services on underground markets. The botnet’s activity has been observed primarily in Asia and Europe, with spikes correlating to the release of new exploit scripts targeting publicly disclosed vulnerabilities.

Security researchers warn that the use of edge devices as SOCKS5 relays complicates attribution and mitigation, as traditional ingress filtering often misses traffic that appears to originate from legitimate internal hosts. The encrypted C2 channel also hinders network‑based detection, requiring defenders to look for anomalous outbound connections or unusual authentication patterns.

Defenders should begin by ensuring that all edge routers and IoT devices run the latest firmware from their manufacturers, especially for Alcatel, NETGEAR and D-Link models known to be targeted. Disabling remote management interfaces such as telnet, SSH and HTTP administration when not required reduces the attack surface exploited by the botnet’s scanner.

Network administrators are advised to monitor outbound traffic for sudden increases in SOCKS5 proxy usage and to enforce strict egress filtering that blocks connections to unknown external IPs on uncommon ports. Implementing multi‑factor authentication for administrative access and regularly reviewing credential stores can further limit the effectiveness of the botnet’s credential sniffing module.

Intelligence briefing updated Aug 17, 2026

Root sourcewww.fortinet.com
Timeline Coverage

Swipe to explore timeline