Cybersecurity researchers at Fortinet have identified Evooo1Bot, a new Linux-based botnet that utilizes Mirai source code to transform compromised internet-facing devices into malicious SOCKS5 proxy nodes.
Key Points
- Evooo1Bot has been active since July 2026, targeting various routers, firewalls, and IP cameras through known security vulnerabilities.
- The malware uses an encrypted command-and-control communication channel over port 443 to blend in with standard HTTPS traffic.
- It features a wide range of capabilities, including credential sniffing, SSH brute-force scanning, DDoS attack execution, and persistent file management.
- The botnet exploits at least 18 distinct vulnerabilities, including flaws in hardware from D-Link, Tenda, Telesquare, and software like Atlassian Confluence and Kubernetes.
- Infected devices are converted into SOCKS5 proxies, allowing attackers to mask malicious traffic and bypass geographic restrictions or internal network security controls.