Evooo1Bot is a new Linux botnet discovered by cybersecurity researchers that exploits known vulnerabilities in edge devices to turn them into SOCKS5 proxies . According to researchers at Fortinet FortiGuard Labs , the malware is based on the source code of the infamous Mirai botnet , but significantly expands its capabilities with encrypted communications, SSH brute-force scanning , credential theft, and a comprehensive arsenal of exploits. The botnet has been active since July 2026 , targeting routers, firewalls, IP cameras, and other devices exposed to the internet.

The leaked Mirai source code has been repeatedly used as the basis for new botnets targeting poorly secured IoT and edge devices. What makes Evooo1Bot particularly dangerous is that it is not designed exclusively for attacks DDoS , but for relaying traffic, establishing a permanent presence, and supporting future attacks. This makes infected devices useful as operational infrastructure for attackers, rather than simply as attack amplifiers.
Fortinet notes that the malware exploits known vulnerabilities in exposed devices, suggesting an opportunistic internet scan for unpatched or misconfigured systems, rather than a targeted attack on a specific victim. Meanwhile, a similar botnet, Tengu , also reported in July 2026, follows the same evolutionary path — from a simple DDoS tool to a fully modular criminal activity platform.
See also: SSHStalker botnet compromises Linux machines via brute-force
Evooo1Bot: What Vulnerabilities Does the Botnet Exploit?
Evooo1Bot of known vulnerabilities. Among the main CVEs it exploits are: CVE-2007-3010 (Alcatel OmniPCX Enterprise Remote Code Execution), CVE-2016-6277 (NETGEAR Multiple Routers RCE), CVE-2018-14558 (Tenda AC7/AC9/AC10 Command Injection), CVE-2019-14931 (Mitsubishi Electric ME-RTU Command Injection), CVE-2020-10987 (Tenda AC1900 RCE), CVE-2021-46422 (Telesquare SDT-CW3B1 Command Injection), CVE-2022-37055 (D-Link Routers Buffer Overflow), CVE-2024-29269 (Telesquare TLR-2005KSH Command Injection), CVE-2025-10123 (D-Link DIR-823X Command Injection) and CVE-2025-55583 (D-Link DIR-868L B1 Command Injection).
Additionally, the CVE attack module includes exploits for vulnerabilities in Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), Zyxel (CVE-2022-30525), TP-Link (CVE-2023-1389), PHP (CVE-2024-4577), D-Link (CVE-2024-10914), and Kubernetes (CVE-2025-1974). The range of targets reveals that the botnet operators are looking for any exposed device, regardless of manufacturer or type.
Once a vulnerability is exploited, a loader shell script named wget.sh, hosted on an external server (91.92.40[.]118), is executed. The script downloads the appropriate botnet binary based on the target device's CPU architecture and then deletes the Bash history to eliminate traces of the attack.

Evooo1Bot: How the SOCKS5 Proxy Module Works
After execution, Evooo1Bot checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communication with the C2 via port 443.The choice of this port is deliberate: it allows the malware to merge with expected HTTPS traffic at the network perimeter, making it extremely difficult to detect. Once the device registers with the C2 server, it awaits further commands.
See also: CVE-2026-53264: AI helped develop Linux root exploit
The botnet supports an extensive command set — reports indicate 28 remote administration commands — that allow the operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the node into a proxy, launch an SSH brute-force scanner, launch DDoS via DNS, TCP, and UDP, and activate an HTTP-based exploit dispatcher.
The proxy component of Evooo1Bot turns an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy, which the threat actor can use as a network relay to conduct other malicious operations and evade detection. The module supports both direct-listen and reverse-relay modes, allowing for multi-session proxying and traffic concealment. According to The Hacker News, this capability significantly increases the value of an infected device to attackers, as the victim’s IP address can be used to cloak malicious traffic, bypass geo-restrictions, or gain access to internal networks via an already compromised machine.
In larger botnets, the same functionality can also be used to create a distributed proxy infrastructure, allowing anonymous traffic forwarding or monetization through residential and enterprise proxy services. This means that infected devices can generate financial profit for the botnet operators, even without launching a direct attack.

Evooo1Bot: Practical Protection Tips for Organizations
Organizations should treat exposed edge devices as high-priority assets. The Evooo1Bot threat highlights the need for systematic vulnerability management across routers, firewalls, IP cameras, and gateway devices — not just servers and endpoints. Default passwords should be changed everywhere, especially on devices with factory-installed credentials that can be exploited by the botnet’s credential sniffer and brute-force scanner.
See also: RustDuck Botnet compromises routers and servers for DDoS
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Specifically, it is recommended to: inventory all internet-facing edge devices and confirm that the firmware is up to date; disable remote management from the public internet unless absolutely necessary; replace default passwords and enforce strong unique credentials ; limit SSH exposure and monitor for brute-force activity. Security teams should also block or be alerted to unusual outbound SOCKS5 behavior and proxy-like connections from devices, monitor for encrypted C2 communications and unusual listening ports, and isolate IoT and gateway equipment from central corporate assets to limit the risk of lateral movement.
The emergence of Evooo1Bot confirms a worrying trend: botnets based on Mirai are evolving from simple DDoS tools to multifunctional platforms for criminal activity. The integration of SOCKS5 proxy, credential sniffing, SSH brute-force, and encrypted C2 communication into a single malware makes infected edge devices valuable tools for attackers — both for hiding their identities and for supporting more complex operations. Timely firmware updates, changing default credentials, and constant monitoring remain the most effective defenses against this growing threat.
