# Your Router Is a Proxy Node Now: Meet Evooo1Bot


The Mirai source code leaked in 2016. Ten years later, researchers are still finding new malware families built on its bones — and each iteration teaches us something about how attackers have matured their ambitions. Evooo1Bot, a modular Linux botnet discovered by Fortinet and active since at least July, is the latest case study. It turns compromised routers and gateway devices into SOCKS5 traffic relay nodes — and unlike many Mirai descendants content with flooding bandwidth for hire, this one has a more diversified business model in mind.


## The Proxy Play


The SOCKS5 module is the piece worth understanding first, because it reframes what this botnet is actually for. SOCKS5 proxies let traffic appear to originate from the device running them — in this case, your home or office router. Evooo1Bot supports both direct listening and reverse-relay modes, and multiple proxy sessions can run simultaneously and independently.


That last detail matters. A botnet operator sitting on tens of thousands of compromised residential routers can quietly sell proxy access to other criminal operations — ad fraud rings, credential stuffers, sanctioned-nation state actors who need IP addresses that look domestic. The residential proxy market, both the legitimate gray-market version and the outright criminal version, has become a real revenue stream. Evooo1Bot's operators appear to have designed for exactly this monetization path.


## What Gets Compromised, and How


The targeting list covers devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — a spread that reflects opportunistic exploitation of known vulnerabilities rather than any surgical targeting. Newer builds have expanded the exploit arsenal considerably: Hikvision cameras, Atlassian Confluence instances, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx controllers, and vulnerable PHP-CGI installations.


That last item — Kubernetes ingress-nginx — stands out. This isn't a consumer router. Ingress-nginx vulnerabilities have been a recurring source of pain in cloud-native environments, and bundling that exploit alongside consumer IoT gear suggests the operators want both the volume of residential IPs and the occasional jackpot of an enterprise system.


Worth noting: Fortinet found that some of the embedded exploits are not correctly implemented and fail. That's not reassuring — it means the operators are iterating and improving, and the broken exploits of today become functional ones in the next build.


## The Architecture of Evasion


Evooo1Bot's operational security is more sophisticated than a typical Mirai fork. The malware performs extensive pre-launch checks for debuggers, sandboxes, virtual machines, containers, and honeypots. C2 communications run encrypted over port 443 — standard HTTPS traffic, blending into normal network noise.


Persistence is belt-and-suspenders: systemd, SysV init, shell profiles, rc.local, and a cron job that re-downloads the payload every five minutes. If you kill the process without removing every one of those persistence mechanisms, it comes back.


When a device is successfully exploited, Bash history is cleared immediately. The malware pulls one of 12 architecture-specific builds — covering the full range of embedded CPU architectures found in consumer and enterprise gateway hardware.


The credential sniffer module is the detail that should make network defenders uncomfortable. It monitors /proc/net/tcp and attempts to capture HTTP Basic Authentication credentials and session cookies from traffic transiting the compromised device. If that device sits inline — a router, a gateway — this is a passive credential harvest with no active probing required.


## The SSH Brute-Force Picture


The SSH scanner module uses 150 username and password combinations, specifically targeting enterprise-oriented accounts. It includes post-login checks to avoid honeypots, which reflects a level of operational care. 150 combinations isn't a massive dictionary, but it's curated — these are the credentials that actually work on managed infrastructure that someone forgot to lock down.


The DDoS capability, inherited from Mirai, supports 16 flood methods: UDP, DNS, SYN, ACK, GRE, fragmented TCP, and HTTP floods with customizable request parameters. This isn't new, but it provides the threat actor leverage — botnet-for-hire, proxy-for-hire, or both simultaneously.


## What Defenders Need to Do Right Now


The standard advice — patch firmware, change default credentials, disable remote access panels, replace end-of-life devices — is all still true and still largely ignored. A few more specific points:


  • If you're running Confluence, Zyxel, or ingress-nginx, check whether Evooo1Bot's exploit targets match your versions. The fact that some exploits are broken doesn't mean they all are.
  • Monitor for encrypted traffic on port 443 from edge devices that have no business making outbound HTTPS connections. A router initiating TLS sessions to an external IP is not normal.
  • Audit your cron jobs and systemd units on Linux-based gateway devices. A re-downloading cron job firing every five minutes is detectable if you're looking.
  • Check /proc/net/tcp access patterns. A process reading network state tables on a device that shouldn't be running custom software is a red flag.

  • ---


    ## HackWire Analysis


    Evooo1Bot is worth watching not because it's technically groundbreaking — it isn't — but because it represents the continued maturation of the Mirai ecosystem into something more businesslike.


    The 2016 Mirai source leak was a watershed moment, but the botnets that followed were mostly crude: hijack a device, point it at a target, flood. The DDoS-for-hire market that grew out of that era was straightforward criminal infrastructure. What's changed is the proxy layer. Residential proxy services — both the quasi-legitimate commercial kind and the outright criminal kind — have become a substantial market, and botnet operators have noticed.


    Evooo1Bot's SOCKS5 monetization path is a sign of that shift. The same compromised router that helps attack a target can also be quietly rented out as a proxy exit node, making the botnet continuously profitable rather than just episodically useful for DDoS campaigns. This is the botnet-as-service model evolving.


    The Kubernetes ingress-nginx target deserves more attention than it's getting in initial coverage. Consumer IoT compromise is old news. But a botnet operator who can drop the same malware on both a home router and an enterprise Kubernetes cluster — and then use both as proxy nodes — has dramatically expanded their network's apparent legitimacy. Traffic exiting through a corporate cloud environment looks very different from traffic exiting through a residential IP block.


    The broken exploits are the most interesting operational detail. Operators who know some of their weapons don't work yet are still shipping them, which suggests rapid iteration. The next build of Evooo1Bot may have those fixed. Defenders have a narrow window where detection is easier because the malware is failing loudly — use it.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)