Evooo1Bot Mirai variant is exploiting Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare devices

A newly documented Mirai-based botnet called Evooo1Bot has been actively compromising internet-facing routers and other edge devices from several vendors for at least a month. FortiGuard says it exploits unpatched flaws in devices from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda, and Telesquare, though no CVE list or victim count was provided. The Linux malware adds encrypted command-and-control traffic, honeypot avoidance, credential sniffing for unchanged default logins, and SOCKS proxy support that can hide attacker traffic and enable follow-on intrusions.
Why it matters: Organizations and consumers with exposed routers, cameras, firewalls, and similar edge hardware may be at risk now, especially if devices are old, internet-facing, or still use default credentials. Defenders should patch affected devices, disable direct internet exposure where possible, rotate passwords, and look for signs of unauthorized proxying or botnet activity.

Sources

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
SecurityWeek News 2026.08.21 91% relevant
This article adds technical detail that Evooo1Bot is modular and includes an SSH brute-forcer, credential sniffer, and SOCKS5 relay module that can turn infected devices into proxy nodes, beyond standard DDoS use.
Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
info@thehackernews.com (The Hacker News) 2026.08.17 97% relevant
This appears to be the same underlying botnet campaign, adding reporting that Evooo1Bot is a Linux botnet using known flaws to convert compromised edge devices into SOCKS5 proxy nodes.
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Bill Toulas 2026.08.15 97% relevant
This is the same underlying event: Fortinet’s reporting on the Evooo1Bot Mirai-based botnet targeting the same router and gateway vendors. The article adds concrete details on Evooo1Bot’s SOCKS5 traffic-relay function, credential sniffing, SSH brute forcing, persistence mechanisms, encrypted command-and-control over port 443, and the broader embedded exploit set including Hikvision, Confluence, Zyxel, TP-Link, WSO2, ingress-nginx, and PHP-CGI targets.
New Mirai variant adds stealth capabilities to notorious botnet code
2026.08.13 100% relevant
This article appears to be the first tracked report establishing Evooo1Bot as a distinct Mirai-derived malware campaign exploiting multiple vendors' internet-facing devices.
← Back to all stories