Vulnerabilities & Exploits · IoT / OT Attack

Evooo1Bot Turns Edge CVEs Into Proxy Nodes

Researchers say the Mirai-derived Evooo1Bot is now actively exploiting known router and gateway flaws to infect internet-facing devices and recruit them as long-lived SOCKS5 proxy nodes. Fortinet says the botnet has been in the wild since July 2026 and is targeting edge gear from vendors including NETGEAR, Tenda, D-Link, Telesquare, Alcatel, Mitsubishi Electric, and Zyxel.

The malware still carries Mirai’s DDoS engine, but it also adds a SOCKS relay, SSH brute-force scanner, and credential sniffer. In plain terms, a compromised gateway can be used as a tunnel for attacker traffic and for harvesting login material, so the infection is useful even when no flood is happening. That makes cleanup about more than removing one bot process: the box itself can be turned into durable external infrastructure.

If your trust model treats edge appliances as just perimeter devices, this campaign shows they can become attacker-owned transit that hides source IPs and supports follow-on access attempts. The exposure is highest where routers and branch gateways are internet-facing and old firmware or exposed services still line up with the CVEs Evooo1Bot is already using.

5 sources · Aug 17

CVEs in this update

8 CVEs

6 critical · 2 high · 0 medium · 0 low

5 in CISA KEV · 8 with EPSS above 1%

2 with functional or packaged public exploit code

Highest severity: CVE-2007-3010 · 9.8 CRITICAL

Highest EPSS: CVE-2016-6277 · 99.8%

Timeline

Sources

Part of the PlainSec briefing for 2026-08-14

Every edition of this story: Evooo1Bot Turns Edge CVEs Into Proxy Nodes

More from today