HackMyIP
← Back to News
2026-08-17 The Hacker News

Evooo1Bot Linux Botnet Hijacks Edge Devices Into SOCKS5 Proxies

MalwareVulnerabilityThreat Intel

Fortinet FortiGuard Labs has identified a previously undocumented Linux botnet family dubbed Evooo1Bot, active in the wild since July 2026, that derives its core functionality from the leaked Mirai source code while significantly extending the original framework. While it reuses Mirai's DDoS engine, Evooo1Bot adds encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities. The botnet specifically weaponizes more than a decade of CVEs against edge devices, including CVE-2007-3010 (Alcatel OmniPCX), CVE-2016-6277 (NETGEAR routers), CVE-2018-14558 and CVE-2020-10987 (Tenda routers), CVE-2019-14931 (Mitsubishi ME-RTU devices), CVE-2021-46422 and CVE-2024-29269 (Telesquare devices), CVE-2022-37055 (D-Link routers), CVE-2025-10123 (D-Link DIR-823X), and CVE-2025-55583 (D-Link DIR-868L B1).

Successful exploitation triggers the execution of a loader shell script ("wget.sh") hosted on 91.92.40[.]118, which retrieves an architecture-compatible botnet binary before clearing Bash history to erase forensic traces. On launch, the binary performs anti-analysis checks for sandboxes and virtual environments, then establishes encrypted C2 communications over port 443 to blend in with expected HTTPS traffic at the network perimeter. Once registered, the infected host awaits operator commands covering persistence installation, binary updates, bot termination, file upload/download, interactive shell access, HTTP Basic Authorization and Cookie header interception, SSH brute-forcing, and DDoS attacks over DNS, TCP, and UDP. Operators can also fire an HTTP-based exploit dispatcher targeting additional flaws in Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), and WSO2 (CVE-2022-29464) servers.

The SOCKS5 proxy conversion module is the most strategically concerning capability, effectively weaponizing compromised edge routers and IoT devices as anonymization infrastructure for the operators' other criminal activity. Organizations concerned about traffic hijacking should run a VPN/proxy detector against outbound connections and use a port scanner to audit internet-facing devices for exposed management interfaces. Given the botnet's credential-sniffing and SSH brute-force modules, defenders should also verify account exposure with a password checker and enforce key-based SSH authentication across all edge infrastructure to neutralize this evolving Linux threat.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →Email Breach Check →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →