Published Security3 min read
Evooo1Bot turns edge gear into rentable proxy stock, and the tell is outbound
Fortinet says the Mirai-derived botnet bolts a SOCKS5 relay onto compromised routers, cameras and Confluence hosts. Sellable proxy capacity changes what you hunt for.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Fortinet researchers documented a new Mirai-based modular Linux botnet called Evooo1Bot that targets internet-facing gateway devices and turns them into SOCKS5 traffic relay nodes.
- Evooo1Bot's capabilities extend beyond proxy conversion to include credential theft, SSH brute-forcing and launching DDoS attacks.
- Since at least July, Evooo1Bot has targeted devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link across various regions by exploiting known vulnerabilities.
- Fortinet researchers said the malware reuses the DDoS engine from the publicly leaked Mirai source code and extends the framework with encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer and an integrated exploit arsenal targeting multiple known vulnerabilities.
- Newer Evooo1Bot builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx and vulnerable PHP-CGI installations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Fortinet researchers have documented a modular, Mirai-based Linux botnet called Evooo1Bot that has been converting internet-facing gateway devices into SOCKS5 traffic relay nodes since at least July, hitting kit from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link across multiple regions via known vulnerabilities [1][3]. The flood engine is lifted from the leaked Mirai source, but the part that changes the calculus is the relay: Fortinet says proxying sessions run independently and several can be open at once, which opens monetisation through residential proxy services if the botnet gets big enough [4][13].
That is the shift worth internalising. An edge device conscripted for DDoS is someone else's problem for a few hours. An edge device sold as proxy capacity is a long-lived asset for its operator, and the traffic riding through it is somebody's fraud, scraping or intrusion, sourced from your address space. Fortinet's description of the SOCKS5 module covers both direct listening and reverse-relay modes, useful for concealing traffic, working around geographic restrictions, or reaching networks through the compromised host [12].
The target list has moved past consumer routers. Newer builds carry a separate exploitation module aimed at Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx and vulnerable PHP-CGI installations [5], eight product families in one payload [17]. Confluence and ingress-nginx are not IoT. They are inside the perimeter, and a relay planted there is a pivot as much as a proxy.
The build quality is mixed, which is worth knowing before anyone panics. Fortinet notes that some embedded exploits are not implemented correctly and simply fail [6]. What does work is unglamorous and effective: on successful exploitation a script pulls one of 12 architecture-matched builds and clears Bash history [7]; C2 runs encrypted over port 443, after checks for debuggers, security tooling, sandboxes, VMs, containers and honeypots [8]; persistence is spread across systemd, SysV init, shell profiles and rc.local, with a cron job re-fetching the payload every five minutes [9]. That cadence is roughly 288 download attempts per device per day [18], which is loud on egress even when it is quiet on the host.
There is also collection. A credential sniffer watches /proc/net/tcp and grabs HTTP Basic Authentication and Cookie headers [11], an SSH scanner works 150 username and password pairs skewed toward enterprise accounts and runs post-login checks to dodge honeypots [14], and an interactive shell plus file transfer gives operators hands-on access [10]. The inherited DDoS module supports 16 flood methods including UDP, DNS, SYN, ACK, GRE, fragmented TCP and a customisable HTTP flood [15].
Hunting guidance follows from the architecture rather than from any indicator list. Devices whose normal role is to answer connections, not initiate them, should not be establishing persistent outbound TLS sessions on 443, nor fetching payloads on a five-minute clock [8][9]. Fortinet's hygiene advice is the usual and still unmet baseline: patch firmware, kill default admin credentials, disable remote management panels, and replace gear the vendor no longer supports [16].
Watch two things: whether the botnet reaches the scale where the proxy capacity actually sells [13], and whether the next builds fix the exploits that currently misfire [6]. The second is cheap for the operator and expensive for anyone still running end-of-support ingress.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Fortinet researchers documented a new Mirai-based modular Linux botnet called Evooo1Bot that targets internet-facing gateway devices and turns them into SOCKS5 traffic relay nodes.
- [2]
Evooo1Bot's capabilities extend beyond proxy conversion to include credential theft, SSH brute-forcing and launching DDoS attacks.
- [3]
Since at least July, Evooo1Bot has targeted devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link across various regions by exploiting known vulnerabilities.
- [4]
Fortinet researchers said the malware reuses the DDoS engine from the publicly leaked Mirai source code and extends the framework with encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer and an integrated exploit arsenal targeting multiple known vulnerabilities.
- [5]
Newer Evooo1Bot builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx and vulnerable PHP-CGI installations.
- [6]
Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation.
Sources & coverage · 3 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 15New Evooo1Bot Linux botnet turns routers into traffic relay nodes
- thehackernews.com6d ago



