AUTO-UPDATED

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers at Fortinet have identified Evooo1Bot, a new Linux-based botnet that utilizes Mirai source code to transform compromised internet-facing devices into malicious SOCKS5 proxy nodes.

Key Points

  • Evooo1Bot has been active since July 2026, targeting various routers, firewalls, and IP cameras through known security vulnerabilities.
  • The malware uses an encrypted command-and-control communication channel over port 443 to blend in with standard HTTPS traffic.
  • It features a wide range of capabilities, including credential sniffing, SSH brute-force scanning, DDoS attack execution, and persistent file management.
  • The botnet exploits at least 18 distinct vulnerabilities, including flaws in hardware from D-Link, Tenda, Telesquare, and software like Atlassian Confluence and Kubernetes.
  • Infected devices are converted into SOCKS5 proxies, allowing attackers to mask malicious traffic and bypass geographic restrictions or internal network security controls.

Why it Matters

This botnet poses a significant threat by turning common edge devices into a distributed infrastructure for anonymous traffic forwarding and further cyberattacks. By leveraging residential and enterprise IP addresses, attackers can effectively hide their origins and bypass traditional network security perimeters.
Internet Published by info@thehackernews.com (The Hacker News)
Read original