Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Evooo1Bot is a previously undocumented Linux botnet family derived from Mirai source code that transforms internet-facing edge devices into SOCKS5 proxies The malware extends Mirai with encrypted C2 communications, SSH brute-force scanning, credential sniffing, and an integrated exploit arsenal targeting 11+ known vulnerabilities Active since July 2026, it weaponizes flaws in routers, IP cameras, and IoT devices from manufacturers including D-Link, Tenda, NETGEAR, and Hikvision The SOCKS5 proxy
Analysis
TL;DR
- Evooo1Bot is a previously undocumented Linux botnet family derived from Mirai source code that transforms internet-facing edge devices into SOCKS5 proxies
- The malware extends Mirai with encrypted C2 communications, SSH brute-force scanning, credential sniffing, and an integrated exploit arsenal targeting 11+ known vulnerabilities
- Active since July 2026, it weaponizes flaws in routers, IP cameras, and IoT devices from manufacturers including D-Link, Tenda, NETGEAR, and Hikvision
- The SOCKS5 proxy capability significantly increases botnet value by enabling anonymous traffic forwarding, geographic restriction bypass, and internal network access through compromised hosts
- Attackers can monetize the distributed proxy infrastructure through residential and enterprise proxy services while evading detection
Why It Matters
This botnet represents an evolution in IoT malware strategy, shifting from pure DDoS capabilities to proxy infrastructure monetization—a model that provides sustained economic incentives for attackers. For AI practitioners and security researchers, it demonstrates how publicly leaked malware source code can be rapidly adapted with modern encryption and evasion techniques, creating new threats that outpace traditional signature-based detection.
Technical Details
- Architecture: Linux-based botnet using Mirai's DDoS engine as foundation, extended with encrypted C2 on port 443 to blend with HTTPS traffic, sandbox/analysis tool detection, and multi-module capability set
- Exploitation: Targets 11 CVEs across multiple vendors—Alcatel OmniPCX (CVE-2007-3010), NETGEAR routers (CVE-2016-6277), Tenda routers (CVE-2018-14558, CVE-2020-10987), Mitsubishi/INEA ME-RTU (CVE-2019-14931), Telesquare devices (CVE-2021-46422, CVE-2024-29269), D-Link routers (CVE-2022-37055, CVE-2025-10123, CVE-2025-55583), plus Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, PHP, and Kubernetes vulnerabilities
- Infection Chain: Exploitation → loader script execution (wget.sh from 91.92.40[.]118) → architecture-specific binary download → Bash history clearing → C2 registration → command execution
- Capabilities: Persistence installation, binary updates, file upload/download, interactive shell, HTTP header interception (Basic Auth and Cookies), SSH brute-force scanning, DNS/TCP/UDP DDoS, SOCKS5 proxy relay, and HTTP-based exploit dispatcher
Industry Insight
- Proxy monetization is the new botnet gold rush: The shift from DDoS-for-hire to distributed proxy services creates persistent economic incentives, meaning botnets will survive longer and adapt faster to countermeasures
- Legacy vulnerability weaponization is accelerating: The botnet's use of CVEs spanning 2007-2025 demonstrates how threat actors maintain comprehensive vulnerability databases and rapidly integrate new exploits—organizations must prioritize patching even "old" vulnerabilities in internet-facing IoT devices
- Encrypted C2 on port 443 defeats perimeter inspection: The intentional use of HTTPS port for command-and-control communications means traditional network monitoring will miss botnet traffic; security teams should implement TLS inspection, behavioral analysis, and DNS-based threat detection rather than relying solely on signature matching
Disclaimer: The above content is generated by AI and is for reference only.