Evooo1Bot Uses Routers as Stealth Proxy Nodes

Fortinet’s Yi Ping Lin said on Aug. 13 that Evooo1Bot, a Mirai-derived Linux botnet, is actively exploiting 10 flaws across Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link edge devices. The campaign has been observed against internet-facing gear rather than a single product line. The bot keeps the familiar Mirai DDoS engine, but it also adds a SOCKS relay. That means a compromised router or RTU can forward other traffic through its own IP address, making the device act like a small anonymous proxy instead of just a disposable flood node. That shifts the cleanup problem from one noisy infection to a longer-lived egress point. If your network relies on source-IP reputation, allowlists, or simple blocking, a compromised edge device can keep obscuring where the real operator sits even after the original botnet payload is removed.

Part of the PlainSec briefing for 2026-08-14

Editions

Sources