A newly documented Mirai-based botnet called Evooo1Bot has been actively compromising internet-facing routers and other edge devices from several vendors for at least a month. FortiGuard says it exploits unpatched flaws in devices from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare, though no CVE list or victim count was provided. The Linux malware adds encrypted command-and-control traffic, honeypot avoidance, credential sniffing for unchanged default logins, and SOCKS proxy support that can hide attacker traffic and enable follow-on intrusions.
Why it matters: Organizations and consumers with exposed routers, cameras, firewalls, and similar edge hardware may be at risk now, especially if devices are old, internet-facing, or still use default credentials. Defenders should patch affected devices, disable direct internet exposure where possible, rotate passwords, and look for signs of unauthorized proxying or botnet activity.
SecurityWeek News
2026.08.21
91% relevant
This article adds technical detail that Evooo1Bot is modular and includes an SSH brute-forcer, credential sniffer, and SOCKS5 relay module that can turn infected devices into proxy nodes, beyond standard DDoS use.
info@thehackernews.com (The Hacker News)
2026.08.17
97% relevant
This appears to be the same underlying botnet campaign, adding reporting that Evooo1Bot is a Linux botnet using known flaws to convert compromised edge devices into SOCKS5 proxy nodes.
Bill Toulas
2026.08.15
97% relevant
This is the same underlying event: Fortinet’s reporting on the Evooo1Bot Mirai-based botnet targeting the same router and gateway vendors. The article adds concrete details on Evooo1Bot’s SOCKS5 traffic-relay function, credential sniffing, SSH brute forcing, persistence mechanisms, encrypted command-and-control over port 443, and the broader embedded exploit set including Hikvision, Confluence, Zyxel, TP-Link, WSO2, ingress-nginx, and PHP-CGI targets.
2026.08.13
100% relevant
This article appears to be the first tracked report establishing Evooo1Bot as a distinct Mirai-derived malware campaign exploiting multiple vendors' internet-facing devices.
← Back to all stories