Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » Evooo1Bot Linux botnet hijacks routers with SOCKS5 relays and credential theft
    Technology

    Evooo1Bot Linux botnet hijacks routers with SOCKS5 relays and credential theft

    Gary BehanBy Gary Behan20/08/2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Evooo1Bot Linux botnet
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A new Mirai-based modular malware called Evooo1Bot Linux botnet has been targeting internet-facing gateway devices since at least July, turning compromised hardware into SOCKS5 traffic relay nodes while also stealing credentials, brute-forcing SSH access, and launching distributed denial-of-service (DDoS) attacks. The malware goes well beyond simple proxy abuse: it arrives with an integrated exploit arsenal, encrypted command-and-control (C2) communications, and enough anti-analysis tricks to make incident response genuinely awkward.

    Researchers at Fortinet‘s FortiGuard Labs published their findings on the botnet family, with the analysis attributed to researcher Yi Ping (Cara) Lin. According to Infosecurity Magazine, Lin shared the analysis on 13 August. The team traced the botnet back to a shared loader URL, 91.92.40[.]118/wget.sh, after observing exploitation of known vulnerabilities with payload callbacks all pointing to the same address, which is how the separate campaigns were connected into a single family.

    What the Evooo1Bot Linux botnet actually does

    Fortinet researchers described the malware as reusing the DDoS engine from the publicly leaked Mirai source code, but extending that framework considerably. The additions include encrypted C2 communications running over port 443, an SSH brute-force scanner, a SOCKS5 relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities. Devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link have all been targeted across various regions.

    Newer builds extend the exploit coverage further, adding modules targeting Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. Fortinet does note, however, that some of the embedded exploits are not correctly implemented, leading to failed exploitation attempts in practice.

    When an exploit lands successfully, a script downloads one of 12 available malware builds matched to the host’s CPU architecture, then clears Bash history to remove traces of the intrusion. Persistence is established through systemd, SysV init, shell profiles, and rc.local, while a cron job attempts to re-download the payload every five minutes, a fairly determined approach to staying alive on a compromised device.

    The malware also runs extensive checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it activates on an infected device. An interactive shell gives operators direct control over compromised systems, and file-transfer commands support both uploads and downloads.

    Credential theft, proxy monetisation, and DDoS

    The credential sniffer module monitors /proc/net/tcp and attempts to capture HTTP Basic Authentication and Cookie headers from passing traffic. It is a passive approach that requires no further exploitation once the device is compromised, making it harder to detect than active attacks.

    The SOCKS5 module supports both direct listening and reverse-relay modes, allowing attackers to conceal malicious traffic, circumvent geographic restrictions, or access internal networks through a compromised device acting as a stepping stone. Fortinet notes that proxying sessions run independently and multiple can be opened simultaneously, which opens the door to monetisation through residential proxy services if the botnet reaches sufficient scale.

    The SSH scanner uses 150 username and password combinations aimed at enterprise-oriented accounts, and performs post-login checks to avoid landing on honeypots. The inherited DDoS module supports 16 flood methods, among them UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood with customisable requests.

    For defenders, the standard advice applies: keep IoT device firmware updated, replace default admin credentials, disable remote access panels where they are not needed, and retire hardware that no longer receives vendor support. The 91.92.40[.]118/wget.sh loader URL identified by Fortinet’s researchers provides a concrete indicator of compromise to add to detection rules.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleClaude AI Text Watermarking: How Anthropic Is Hiding a Statistical Signature in Every Response
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    Claude AI Text Watermarking: How Anthropic Is Hiding a Statistical Signature in Every Response

    19/08/2026

    Operation Klonen Bank Fraud: Four Arrested Over €30M Commerzbank Heist

    19/08/2026

    macOS Screen Sharing exploit actively used to mine Monero, Dutch agency warns

    19/08/2026

    Shell Clop Data Breach Probe Widens as 43 Firms Hit by PTC Flaw

    18/08/2026

    Cameron Curry Brightly Software extortion lands him two years in prison

    18/08/2026

    Apple Threat Notification alerts land again as mercenary spyware campaign hits iPhone users

    18/08/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.