Researchers say the Mirai-derived Evooo1Bot is now actively exploiting known router and gateway flaws to infect internet-facing devices and recruit them as long-lived SOCKS5 proxy nodes. Fortinet says the botnet has been in the wild since July 2026 and is targeting edge gear from vendors including NETGEAR, Tenda, D-Link, Telesquare, Alcatel, Mitsubishi Electric, and Zyxel.
The malware still carries Mirai’s DDoS engine, but it also adds a SOCKS relay, SSH brute-force scanner, and credential sniffer. In plain terms, a compromised gateway can be used as a tunnel for attacker traffic and for harvesting login material, so the infection is useful even when no flood is happening. That makes cleanup about more than removing one bot process: the box itself can be turned into durable external infrastructure.
If your trust model treats edge appliances as just perimeter devices, this campaign shows they can become attacker-owned transit that hides source IPs and supports follow-on access attempts. The exposure is highest where routers and branch gateways are internet-facing and old firmware or exposed services still line up with the CVEs Evooo1Bot is already using.
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.