
Daily Cybersecurity News – August 16, 2026
Evooo1Bot turns Linux routers into SOCKS5 relays
HighWhat happened
A new Mirai-based modular Linux botnet called Evooo1Bot has been active since at least July, compromising internet-facing gateway devices and converting them into SOCKS5 traffic relay nodes.
It reuses Mirai's DDoS engine while adding encrypted C2 communications over port 443, an SSH brute-force scanner, a credential sniffer that monitors /proc/net/tcp for HTTP Basic Auth and cookies, interactive shell access, file transfer, and a SOCKS5 module supporting direct and reverse-relay modes. It exploits known vulnerabilities in devices from multiple vendors, downloads architecture-matched payloads (12 builds), clears Bash history, performs anti-analysis checks, and establishes persistence via systemd, init scripts, profiles, rc.local, and a 5-minute cron re-download job. Newer modules target additional products including Hikvision cameras, Confluence, Zyxel, TP-Link, D-Link NAS, WSO2, Kubernetes ingress-nginx, and PHP-CGI, though some exploits are imperfectly implemented.
Who is affected
Internet-facing Linux-based gateway and router devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link, plus expanded targets such as Hikvision cameras, Atlassian Confluence servers, Zyxel firewalls, TP-Link routers, D-Link NAS, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI setups.
Operators and organizations running these internet-exposed devices are at risk of compromise, with the botnet spreading across various geographic regions.
Why it matters
Compromised routers become proxy nodes that attackers can use to anonymize their traffic, hide origins of further attacks, or relay malicious activity, while the botnet also enables credential theft, SSH brute-forcing, and DDoS.
This expands the attack surface for proxy abuse and secondary compromises, turning everyday edge devices into resilient infrastructure for threat actors and making detection harder due to encrypted C2 and anti-analysis features.
How it could have been prevented
Immediately patch or mitigate known vulnerabilities on internet-facing Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, Hikvision, Zyxel, TP-Link, and related devices. Disable unnecessary remote management and exposure of admin interfaces, SSH, and other services to the internet.
Change default credentials, enforce strong unique passwords, monitor for unusual outbound traffic or SOCKS activity, review persistence mechanisms like cron and systemd units, and isolate or replace end-of-life hardware. Use network segmentation and firewall rules to limit lateral movement and C2 reachability.
Relevant professional terms
- Botnet
- A network of internet-connected devices infected with malware and controlled remotely by an attacker to perform coordinated tasks like attacks or traffic relay.
- SOCKS5 relay
- A proxy mechanism using the SOCKS5 protocol that forwards arbitrary TCP traffic through a compromised host, allowing attackers to route their connections anonymously via the infected device.