ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME23:56:22 UTC
← All briefs
HIGHCyber IntelligenceSunday, August 16, 2026

Evooo1Bot botnet converts routers into covert relay infrastructure

Mirai-based malware targets internet-facing gateways, enslaving them as SOCKS5 proxies to obscure malicious traffic and enable credential theft.

A modular Linux botnet named Evooo1Bot is compromising internet-facing routers and gateway devices, converting them into SOCKS5 traffic relay nodes. The malware, built on the Mirai framework, allows operators to route malicious traffic through infected devices, obscuring the origin of attacks and credential-harvesting operations.

The botnet's modular architecture enables operators to deploy additional capabilities post-compromise. Once a device is infected, it becomes part of a distributed proxy network that can be leased or used internally for further intrusions. The use of compromised home and small-office routers as relay infrastructure complicates attribution and evades network-based detection.

Evooo1Bot joins a growing class of IoT-focused botnets exploiting weak or default credentials on edge devices. The Mirai lineage indicates likely use of known exploits and brute-force techniques against Telnet and SSH services. Operators gain persistent access to devices that typically lack robust logging or endpoint protection, making detection and remediation difficult for device owners.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Organizations face increased risk of credential theft routed through trusted residential IP space.
  • 02ISPs and network defenders lose visibility into attack origins when traffic transits compromised routers.
  • 03Device manufacturers remain under pressure to enforce secure-by-default configurations and timely patching.
Source
BleepingComputer
https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#botnet#mirai#iot security#socks5 proxy#router compromise#linux malware
Related Briefs