VMTech
Discuss a project

Evooo1Bot Botnet Uses Vulnerable Edge Devices as SOCKS5 Relays

Evooo1Bot Botnet Uses Vulnerable Edge Devices as SOCKS5 Relays

Fortinet FortiGuard Labs has identified Evooo1Bot, a previously undocumented Linux botnet family that has been active since July 2026. The malware exploits known vulnerabilities in publicly accessible devices and can convert infected routers, firewalls, IP cameras and other edge systems into SOCKS5 proxy nodes.

Evooo1Bot derives core functionality from the leaked Mirai source code, including its DDoS engine, but adds encrypted command-and-control communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer and an exploit arsenal. This combination gives operators both disruption capabilities and a means to use compromised infrastructure as a relay for subsequent activity.

Exploits deliver an architecture-specific bot binary

The botnet targets a range of known flaws, including vulnerabilities affecting Alcatel OmniPCX Enterprise, NETGEAR routers, Tenda routers, Mitsubishi and INEA ME-RTU devices, Telesquare products and D-Link routers. Successful exploitation runs a loader shell script named wget.sh, hosted on an external server at 91.92.40[.]118.

The loader retrieves a binary compatible with the victim device's CPU architecture and clears Bash history afterwards. On launch, the binary checks for analysis tools, sandboxes and virtual environments. It then establishes encrypted communications with its command-and-control server on port 443, a choice intended to blend into expected HTTPS traffic at the network perimeter.

Proxy function raises the value of compromised devices

After registering with the command-and-control server, the bot waits for instructions. Supported commands include installing persistence, updating or terminating the binary, transferring files, opening an interactive shell, intercepting HTTP Basic Authorization and Cookie headers, launching SSH brute-force scans and initiating DNS, TCP and UDP DDoS attacks.

The HTTP exploit dispatcher can target eight additional flaws affecting Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, PHP, D-Link and Kubernetes. This follows the same broader Mirai-derived threat pattern seen in Mirai variant exploiting TBK DVR vulnerability, where exposed devices and known weaknesses provide a route to botnet growth and DDoS capability.

Its SOCKS component turns an infected edge device into a relay that an operator can use to disguise malicious traffic, bypass geographic restrictions or potentially reach internal networks through an already compromised machine. Fortinet noted that, at scale, such hosts could form distributed proxy infrastructure for anonymous forwarding or monetization through residential and enterprise proxy services.

Business implication

Organizations should identify all internet-facing edge devices, apply available security updates for known vulnerabilities, retire unsupported equipment and investigate unexpected encrypted outbound traffic from perimeter appliances. A compromised device can be used not only for DDoS activity but also to make malicious operations appear to originate from the organisation's own IP address.

#cybersecurity#botnet#iotsecurity#vulnerabilitymanagement
Open analytics
On the site 0 views
min read 3 17.08.2026
Instagram

Evooo1Bot Botnet Uses Vulnerable Edge Devices as SOCKS5 Relays

Open the post on Instagram ↗