New Evooo1Bot malware is quietly turning home routers into criminal traffic relays
Researchers say the Mirai-based botnet has been hijacking gateway devices since July to sell as proxies, steal credentials, and launch attacks.

Key points
- Fortinet has been tracking a new Linux botnet called Evooo1Bot that has been infecting internet-facing routers and gateways since at least July 2024.
- The malware turns compromised devices into SOCKS5 proxies, relays that let criminals bounce their traffic through someone else's internet connection.
- Evooo1Bot targets gear from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, and adds exploits for Hikvision cameras, Atlassian Confluence, Zyxel firewalls and Kubernetes ingress-nginx.
- The bot reuses the leaked Mirai source code for its denial-of-service engine, which floods websites with junk traffic to knock them offline.
- Owners can defend themselves by updating firmware, changing default passwords, and switching off remote admin access.
There's a new family of botnet malware chewing through the exposed edge of the internet, and if you've got an older router sitting behind your TV, this one's worth paying attention to.
Security firm Fortinet has named it Evooo1Bot. As first reported by BleepingComputer, it's a Linux-based bot built on top of the leaked Mirai source code, the same code that powered the huge attacks on internet services back in 2016. The operators have bolted a lot of extra machinery onto it. We first covered Mirai-lineage threats back in May, and Evooo1Bot is the most fully modular variant we've seen since.
In plain terms: it breaks into your router and rents your internet connection out to criminals.
What is Evooo1Bot actually doing?
It hijacks internet-facing gateway devices and turns them into SOCKS5 relay nodes, routing someone else's traffic through your box so it looks like it came from your home. That's valuable to criminals who need to hide where they really are.
The malware does more than proxy work. It steals login details, tries to guess SSH passwords on other machines (SSH is the remote-login system admins use to manage servers), and can join distributed denial-of-service attacks that flood a target until it falls over.
Evooo1Bot has been active since at least July, hitting devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link across multiple regions. Newer builds add exploits for Hikvision cameras, Atlassian Confluence servers, Zyxel firewalls, TP-Link routers, D-Link network storage, WSO2 products, Kubernetes ingress-nginx (a common piece of cloud plumbing) and vulnerable PHP-CGI installs.
Fortinet notes that some of those exploits are coded badly and simply fail. That's sloppy attacker engineering, not a defensive win.
How does it stay hidden?
Once inside, the malware checks whether it's running in a debugger, a sandbox, a honeypot (a fake system researchers set up as bait), or a virtual machine. Any of those detected, it refuses to run.
Otherwise, it talks to its operators over encrypted traffic on port 443, the same port your browser uses for HTTPS, so the chatter blends in with normal web traffic. It installs itself through systemd, SysV init, shell profiles and rc.local, which are the standard ways a Linux box starts programs at boot. A cron job then re-downloads the payload every five minutes, in case anything wipes it.
After a successful break-in, the script clears Bash history. If you're relying on shell history to spot intrusions, you've already lost.
| Module | What it does |
|---|---|
| SOCKS5 relay | Rents the device out as a proxy for criminal traffic |
| SSH scanner | Tries 150 enterprise username and password pairs on other machines |
| Credential sniffer | Reads web logins and cookies passing through the device |
| DDoS engine (Mirai) | 16 flood types including UDP, DNS, SYN and HTTP |
Should ordinary users worry?
Mostly no, but check your router. If you own any of the listed brands and haven't updated the firmware in years, or you still have the default admin password, you're exactly the target.
Four practical steps: update the firmware from the vendor's site, change the admin password, turn off remote management (the web login page reachable from the internet), and replace the device if the manufacturer no longer ships security fixes.
In practice, most of the routers feeding botnets like this are five to ten years old and out of support. That's the real problem, and no amount of clever detection fixes it.



