← Blog · · df00tech

New Mirai-Based Evooo1Bot Botnet Converts Routers Into SOCKS5 Relays

security-news campaign

BleepingComputer reports on a newly identified Linux botnet malware, dubbed Evooo1Bot, which is based on the Mirai codebase and built as a modular threat. According to the report, the malware is targeting internet-facing gateway devices — such as routers — and, once installed, turns them into SOCKS5 traffic relay nodes. No specific vulnerability, CVE, vendor, or victim list has been named in the reporting at this time.

Why It Matters

Compromised routers and gateway devices sit at the network edge and are frequently internet-facing by design, making them attractive targets regardless of the specific access vector used. Converting these devices into SOCKS5 relays gives operators anonymized egress infrastructure that can be used to proxy other malicious traffic — including command-and-control communications, credential stuffing, fraud, or further intrusion activity — while making the true source harder to attribute. Because the malware is Mirai-based, it inherits a lineage known for rapid, opportunistic scanning and infection of embedded and IoT-class Linux devices, which historically has led to large, geographically distributed botnets.

What Defenders Should Watch For

  • Unusual outbound connections from routers, gateways, and other embedded/IoT devices to unfamiliar external IPs, particularly on ports associated with SOCKS5 proxying.
  • Devices exhibiting unexpected process activity, unauthorized configuration changes, or firmware modifications inconsistent with normal management.
  • A spike in inbound scanning or authentication attempts against exposed management interfaces (SSH, Telnet, HTTP/HTTPS admin panels) on perimeter devices.
  • Gateway devices acting as relays for traffic unrelated to their expected function — e.g., a home/office router generating proxy-like traffic patterns to diverse external destinations.
  • As a general hardening measure, ensure router/gateway firmware is current, default credentials are changed, and management interfaces are not exposed to the internet unless strictly necessary.

This is a developing story and the technical details — including the specific infection vector, indicators of compromise, and affected device models — have not yet been fully disclosed in the available reporting. We will monitor for follow-up analysis. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.