New Mirai Variant Evooo1Bot Targets Routers With Stealth Proxy Features
Security researchers at FortiGuard Labs have uncovered a new Linux-based Mirai variant dubbed Evooo1Bot that has been actively exploiting unpatched vulnerabilities in internet-facing hardware for at least a month. The botnet targets routers and other devices from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare, leveraging known flaws to spread and carry out malicious activity. Telemetry from FortiGuard shows infection attempts concentrated across North America, South America, Europe, India, China, and Japan, though the total number of compromised devices remains unclear.
Beyond the standard distributed denial-of-service (DDoS) capabilities inherited from the original Mirai codebase, Evooo1Bot introduces several advanced features that set it apart from conventional Mirai-derived malware. These include encrypted communications with command-and-control servers, an SSH scanner that automatically skips devices identified as honeypots, and a credential sniffer that searches for default factory usernames and passwords that have never been changed. The malware also abuses the SOCKS protocol to transform compromised routers, firewalls, and IP cameras into persistent proxy nodes, allowing attackers to mask their true origin and pivot into internal networks. Network administrators can use a port scanner to identify exposed services and a password checker to verify that default credentials have been replaced with strong, unique alternatives.
"These capabilities place Evooo1Bot well beyond the technical baseline of conventional Mirai-derived malware," FortiGuard Labs noted, calling the SOCKS proxy abuse "arguably the most operationally significant" feature. The SOCKS functionality effectively turns every infected edge device into an anonymized relay, enabling follow-on intrusions through the victim's own infrastructure. Security teams investigating suspicious traffic from their networks can run a VPN/proxy detector to determine whether outbound connections are being routed through known proxy nodes, which may indicate a compromised host on the perimeter.
The original Mirai source code was publicly released in 2016 and has since spawned dozens of variants. Law enforcement agencies have ramped up efforts to dismantle these networks, with the U.S., Canada, and Germany jointly targeting the Aisuru and KimWolf botnets in March. A Canadian man was charged in May with allegedly running KimWolf. Evooo1Bot's emergence underscores the persistent supply chain of Mirai-derived threats and the ongoing risk posed by unpatched consumer and enterprise networking gear.