Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Erdogan says Egypt could join Turkiye-Saudi-Pakistan defence pact | Al Jazeera News

    August 15, 2026

    I used OpenFactory to build my own Linux distro overnight – this AI tool is going to be big

    August 15, 2026

    Bitcoin $1M By 2030 Is ‘Mathematically Impossible’ Says Markus Thielen

    August 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Erdogan says Egypt could join Turkiye-Saudi-Pakistan defence pact | Al Jazeera News
    • I used OpenFactory to build my own Linux distro overnight – this AI tool is going to be big
    • Bitcoin $1M By 2030 Is ‘Mathematically Impossible’ Says Markus Thielen
    • John Salehe helped shape Tanzania’s community conservation movement
    • South Korea president proposes talks with Pyongyang to formally end Korean War
    • Hungary uses sunken barges to raise Danube River to keep nuclear plant going – POLITICO
    • Dell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs
    • New Evooo1Bot Linux botnet turns routers into traffic relay nodes
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Evooo1Bot Linux botnet turns routers into traffic relay nodes

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 15, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.

    The malware’s capabilities extend beyond turning devices into proxy nodes and include credential theft, SSH brute-forcing, and launching distributed denial-of-service (DDoS) attacks.

    Since at least July, Evooo1Bot has been targeting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions by exploiting known vulnerabilities.

    image
    Evooo1Bot's current geographical spread
    Evooo1Bot’s current geographical spread
    Source: Fortinet

    “While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,” Fortinet researchers found.

    Newer builds include a separate vulnerability-exploitation module targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations.

    However, Fortinet notes that some of the embedded exploits are not correctly implemented, leading to failed exploitation.

    When leveraging an exploit successfully, a script downloads one of the 12 available malware builds that match the host’s CPU architecture, then clears Bash history to wipe traces of the attack.

    Evooo1Bot uses encrypted command-and-control (C2) communications over port 443 and performs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it launches on the infected device.

    Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes.

    The malware's modules
    The malware’s modules
    Source: Fortinet

    An interactive shell gives operators direct control over compromised systems, while file-transfer commands support uploads and downloads.

    The malware also features a credential sniffer module that monitors ‘/proc/net/tcp’ and attempts to capture HTTP Basic Authentication and Cookie headers.

    The SOCKS5 module supports direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or potentially access networks through compromised systems.

    Fortinet says proxying sessions run independently, and multiple can be opened simultaneously, allowing monetization through residential proxy services if the botnet grows large enough.

    The SSH scanner module uses 150 username and password combinations for enterprise-oriented accounts, and performs post-login checks to avoid honeypots.

    Finally, the DDoS module that was inherited by Mirai supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customizable requests.

    To defend against botnet malware, keep your IoT devices’ firmware updated, replace default admin credentials, turn off remote access panels, and replace devices when the vendor no longer provides support for them.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Botnet Evooo1Bot Linux nodes Relay routers Traffic turns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    I used OpenFactory to build my own Linux distro overnight – this AI tool is going to be big

    AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

    Hackers Exploiting Unpatched GeoServer Zero-Day

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    RingCentral data breach exposed info of 1.6 million accounts

    14,000 Trezor Customers Impacted by Data Breach at ShipMonk

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Erdogan says Egypt could join Turkiye-Saudi-Pakistan defence pact | Al Jazeera News

    August 15, 2026

    I used OpenFactory to build my own Linux distro overnight – this AI tool is going to be big

    August 15, 2026

    Bitcoin $1M By 2030 Is ‘Mathematically Impossible’ Says Markus Thielen

    August 15, 2026

    John Salehe helped shape Tanzania’s community conservation movement

    August 15, 2026
    Latest Posts

    Why two public companies quietly liquidated 511 Bitcoin in 24 hours to escape $31.7 million in debt

    July 26, 2026

    TechCrunch Mobility: Uber bets on its former CEO

    July 26, 2026

    Ed Miliband indicates development and climate will be at heart of UK foreign policy | World Bank

    July 26, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Erdogan says Egypt could join Turkiye-Saudi-Pakistan defence pact | Al Jazeera News

    August 15, 2026

    I used OpenFactory to build my own Linux distro overnight – this AI tool is going to be big

    August 15, 2026

    Bitcoin $1M By 2030 Is ‘Mathematically Impossible’ Says Markus Thielen

    August 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.