Cybersecurity

Evooo1Bot Malware Network Turns Routers into Traffic Relay Nodes

Researchers have identified a new Mirai-based malicious network targeting internet-connected gateway devices and turning them into SOCKS5 nodes for relaying traffic, with capabilities for stealing credentials and conducting DDoS attacks. Evooo1Bot exploits known vulnerabilities in multiple devices and products and uses advanced stealth and persistence mechanisms.

2026-08-15
3 min read
12 views
فريق تحرير certi.news
Evooo1Bot Malware Network Turns Routers into Traffic Relay Nodes

The new Evooo1Bot malicious botnet targets internet-connected gateway devices, including routers as well as some cameras, firewalls, and network-attached storage devices, with the aim of turning them into traffic relay nodes through the SOCKS5 protocol. The malware, built on the Mirai framework, combines this functionality with other capabilities, including credential theft, SSH service scanning, and distributed denial-of-service attacks.

According to available information, the campaign has targeted devices since at least July and has included products from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link in various regions. Fortinet researchers said Evooo1Bot reuses a DDoS attack engine from the leaked Mirai source code, but expands the framework with encrypted communications capabilities with command-and-control servers, an SSH attack scanner, a SOCKS relay module, a credential sensor, and a built-in set of exploits.

Targeting Multiple Products and Vulnerabilities

The latest versions include a separate vulnerability exploitation module targeting Hikvision cameras, Atlassian Confluence products, Zyxel firewalls, TP-Link devices, D-Link NAS units, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. However, Fortinet researchers noted that some of the embedded exploits were implemented incorrectly, causing intrusion attempts to fail.

When exploitation succeeds, the malware downloads one of 12 available payload versions, matching the processor architecture of the targeted device, and then clears the Bash history in an attempt to remove traces of the attack. It also checks for debugging tools, security software, testing environments, sandboxes, virtual machines, containers, and honeypots before beginning operations on the infected device.

Traffic Relaying and Device Control

Evooo1Bot establishes persistence through systemd, SysV init, shell profile files, and rc.local, while a cron task attempts to redownload the payload every five minutes. The botnet operators are given access to an interactive shell for direct control of compromised systems, along with commands for uploading and downloading files.

The credential sensor monitors /proc/net/tcp and attempts to capture HTTP Basic Authentication and Cookie headers. The SOCKS5 module supports both direct listening mode and reverse relay mode, enabling attackers to conceal malicious traffic, bypass geographic restrictions, or attempt to access networks through compromised systems. Relay sessions operate independently, with the ability to open multiple sessions simultaneously, which could enable commercial exploitation of the network through residential proxy services if it expands.

SSH Scanning and DDoS Attacks

The malware's SSH scanner uses 150 username-and-password combinations for accounts aimed at enterprise environments, then performs checks after login to avoid honeypots. The DDoS module inherited from Mirai supports 16 flooding methods, including UDP, DNS, SYN, ACK, GRE, and fragmented TCP, as well as HTTP flooding with customizable requests.

To reduce the risk posed by this malware, the guidance recommends updating the firmware of Internet of Things devices, replacing default administrative credentials, disabling remote-access panels, and replacing devices whose vendors have stopped providing support.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news