# Evooo1Bot Is What Happens When Mirai Grows Up
The Mirai source code leaked in October 2016, and the internet has been living with the consequences ever since. Hundreds of copycat botnets followed — most of them functionally identical, just DDoS cannons pointed at whoever the operator wanted to extort or silence that week. Security teams learned to treat them as commodity noise.
Evooo1Bot isn't commodity noise.
Researchers at Fortiguard Labs published findings this past Friday on a Linux botnet that has been quietly expanding since at least July, targeting edge devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. The name comes from a hardcoded string — "evooo1" — embedded in every binary. The capabilities go considerably further than the name suggests.
## DDoS Was Just the Starting Point
Every Mirai derivative inherits the original's distributed denial-of-service engine, and Evooo1Bot is no exception. But Fortiguard researcher Cara Lin described it as something architecturally different: "a significantly more capable and modular framework" that treats DDoS as one feature among many rather than the whole product.
What distinguishes it:
That last item deserves a moment. The oldest CVEs in Evooo1Bot's arsenal are nearly two decades old. These aren't zero-days being burned by nation-state actors. They're ancient, publicly documented flaws on devices that manufacturers stopped updating years ago and owners never thought twice about. The botnet doesn't need to be clever. It just needs the vulnerabilities to still be there — and they are.
## Why the SOCKS Relay Changes the Threat Model
The DDoS angle gets the headlines because it's disruptive and visible. The SOCKS relay module is quieter and more dangerous in the long run.
A compromised device running a SOCKS relay becomes a hop point — a node in an attacker-controlled proxy network. Traffic routed through it appears to originate from that device's IP address, not from the attacker's actual infrastructure. This has real value in criminal markets: residential and edge-device proxy services sell access to these compromised nodes to other threat actors who want their activity to look legitimate.
The implication is that a NETGEAR router running Evooo1Bot isn't just a DDoS soldier. It's potentially for sale as a proxy exit node. The device owner's IP address ends up in logs associated with fraud, credential stuffing, reconnaissance, or worse — and they have no idea.
This isn't a new concept. Residential proxy networks have been a staple of criminal infrastructure for years. What's notable here is that the capability is now bundled directly into a Mirai derivative, lowering the barrier for botnet operators to stand up their own proxy services or monetize compromised devices through multiple channels simultaneously.
## The Vendors on the Target List
Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link. These aren't obscure brands. They represent routers, modems, and network equipment common in small businesses, branch offices, telecom infrastructure, and homes. Many of the devices running these brands in the wild are years past their supported firmware window.
Fortiguard's IPS telemetry caught the botnet through payload callbacks all pointing to the same loader URL. That kind of operational pattern — consistent callback infrastructure — suggests an operator who isn't particularly worried about takedown pressure, at least not yet.
The exploit arsenal covering CVEs from 2007 onward tells its own story. Evooo1Bot's operators understand that patches never reached most of the devices they're targeting. Why burn novel exploitation techniques when the old ones still work?
## What Defenders Actually Need to Do
If you manage any of the affected device categories — and most enterprise networks have legacy edge equipment somewhere — the immediate priorities are:
Organizations running industrial environments should note Mitsubishi Electric's presence on the target list. That intersection of OT hardware and botnet exploitation isn't new, but it remains underappreciated.
---
## HackWire Analysis
The Mirai source code leak was one of the most consequential moments in the history of botnet proliferation, and a decade later we're still feeling the fallout — except now the derivatives are getting smarter.
Evooo1Bot represents a maturation that the security community should track closely. The original Mirai was a blunt instrument built for DDoS volume. What we're seeing now is the logical next phase: botnet operators who understand that persistent, multi-purpose control over a device is worth more than a single DDoS capability. The credential sniffer and SOCKS relay aren't just feature additions — they're revenue diversification strategies.
The 2007 CVEs being exploited in 2026 are the part of this story getting insufficient attention. There's a persistent fantasy in enterprise security that old vulnerabilities age out of relevance. They don't. They become easier to exploit as tools mature and harder to patch as device support ends. Every device running unpatched firmware from an abandoned product line is permanently available attack surface.
What's also missing from most coverage of Mirai derivatives is the proxy economy angle. Criminal markets selling residential and edge-device proxy access have grown substantially over the past three years. Botnets like Evooo1Bot don't just threaten their victims with DDoS — they threaten anyone downstream whose traffic gets misattributed to a compromised node. The SOCKS relay capability makes every infected device a liability for the IP reputation of its owner and a resource for whoever purchases access to the proxy network.
Defenders should treat this as a reminder that "old and boring" vulnerabilities in "old and boring" equipment are exactly what modern botnet operators are counting on them to ignore.
— HackWire Editorial
---
## Related Coverage