Evooo1Bot hijacks routers to relay internet traffic

A new strain of malware is quietly turning everyday routers into unwitting traffic relays for cybercriminals. Dubbed Evooo1Bot, this Linux-based botnet borrows heavily from the infamous Mirai malware, repurposing vulnerable internet-facing gateway devices as SOCKS5 proxy nodes. Once infected, these routers can be used to obscure the origin of malicious traffic, complicating investigations and enabling a range of illicit activities.
A familiar threat with a fresh twist
Evooo1Bot is not the first botnet to target routers, but its approach highlights an ongoing evolution in cybercriminal tactics. Like Mirai, it scans for devices with weak or default credentials, exploits unpatched vulnerabilities, and then establishes persistence. However, instead of focusing solely on DDoS attacks, Evooo1Bot expands the botnet’s utility by converting compromised routers into SOCKS5 proxies. This allows threat actors to route traffic through these devices, masking their true IP addresses and complicating efforts to trace malicious activity back to its source.
Security researchers note that the malware’s modular design suggests it could be adapted for additional malicious functions in the future. The botnet’s command-and-control infrastructure appears to be actively maintained, with updates that enhance its stealth and resilience. While the scale of the current campaign remains unclear, the use of SOCKS5 proxies indicates a shift toward more sophisticated, harder-to-detect operations.
Why it matters
The rise of Evooo1Bot underscores a growing trend: botnets are no longer just tools for brute-force attacks, but also infrastructure for cybercrime. By repurposing consumer and enterprise routers as traffic relays, threat actors can evade detection while monetizing compromised devices through proxy services or affiliate programs. This development places a renewed emphasis on router security, as patching and credential hygiene become critical defenses against botnet recruitment. For organizations and individuals alike, the message is clear—unsecured network devices are no longer just potential entry points, but active participants in criminal ecosystems.
Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

