Vulnerabilities · 42 days ago
Researchers say the Mirai-derived Evooo1Bot is now actively exploiting known router and gateway flaws to infect internet-facing devices and recruit them as long-lived SOCKS5 proxy nodes. Fortinet says the botnet has been in the wild since July 2026 and is targeting edge gear from vendors including NETGEAR, Tenda, D-Link, Telesquare, Alcatel, Mitsubishi Electric, and Zyxel.
The malware still carries Mirai’s DDoS engine, but it also adds a SOCKS relay, SSH brute-force scanner, and credential sniffer. In plain terms, a compromised gateway can be used as a tunnel for attacker traffic and for harvesting login material, so the infection is useful even when no flood is happening. That makes cleanup about more than removing one bot process: the box itself can be turned into durable external infrastructure.
If your trust model treats edge appliances as just perimeter devices, this campaign shows they can become attacker-owned transit that hides source IPs and supports follow-on access attempts. The exposure is highest where routers and branch gateways are internet-facing and old firmware or exposed services still line up with the CVEs Evooo1Bot is already using.
CVEs in this update
8 CVEs
6 critical · 2 high · 0 medium · 0 low
5 in CISA KEV · 8 with EPSS above 1%
2 with functional or packaged public exploit code
Highest severity: CVE-2007-3010 · 9.8 CRITICAL
Highest EPSS: CVE-2016-6277 · 99.8%
5 sources covering this story
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure.
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Evooo1Bot exploits known flaws to infect Linux edge devices, then adds SOCKS5 proxying, SSH brute force, credential theft, and DDoS.
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
The Record from Recorded Future
New Mirai variant adds stealth capabilities to notorious botnet code
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
Part of the PlainSec briefing for 2026-08-18