discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

A newly documented Linux botnet dubbed Evooo1Bot, built on Mirai source code, weaponizes known vulnerabilities in routers and edge devices to recruit them as SOCKS5 proxy nodes and DDoS engines.

By Ravie Lakshmanan·Aug 17·thehackernews.com·3 min read

Intelligence analysis by Llama

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
Image: thehackernews.com

Fortinet FortiGuard Labs details Evooo1Bot, a Linux botnet active since July 2026 that mirrors Mirai's DDoS engine but adds encrypted C2, SSH brute-forcing, credential sniffing, and a SOCKS5 proxy module. It exploits a long list of old and recent CVEs in routers, IP cameras, and other edge gear.

Why it matters

Evolved Mirai variants that monetize infected hosts as residential proxy nodes are a growing trend that turns ordinary consumer and enterprise edge devices into infrastructure for further attacks, fraud, and anonymized crime.

Imagine a gang breaking into old Wi-Fi routers, baby monitors, and office cameras because their owners never updated them. Once inside, they turn each gadget into a secret tunnel that hides where the gang's internet traffic is really coming from, and they can also flood websites with junk traffic to knock them offline.

Analysis

A Loader on 91.92.40[.]118

Evooo1Bot enters a target by exploiting one of more than a dozen listed CVEs spanning nearly two decades of unpatched bugs, from a 2007 Alcatel OmniPCX Enterprise remote code execution flaw (CVE-2007-3010) to 2025-era command injection issues in D-Link and Telesquare gear. After a successful exploit, the attackers drop a shell loader called "wget.sh" from the IP address 91.92.40[.]118, which fingerprints the CPU architecture, fetches the matching bot binary, and immediately clears Bash history to scrub forensic traces. The binary itself is evasive by design, checking for analysis tools, sandboxes, and virtual machines before reaching out to its command-and-control server on TCP port 443, a deliberate choice that lets the encrypted traffic blend in with ordinary HTTPS at the network perimeter.

Mirai's DDoS Engine Plus a SOCKS5 Payoff

According to Fortinet FortiGuard Labs, the malware reuses the publicly leaked Mirai source code as its distributed denial-of-service engine, which gives the operators familiar DNS, TCP, and UDP flood capabilities out of the box. On top of that, the variant layers in an SSH brute-force scanner, a credential sniffer that intercepts HTTP Basic Authorization and Cookie headers, a file upload/download channel, an interactive shell, and an HTTP-based exploit dispatcher for eight additional CVEs affecting products from Hikvision, Atlassian Confluence, WSO2, Zyxel, TP-Link, PHP, D-Link, and Kubernetes. The SOCKS5 proxy module is the differentiator, because it transforms an infected router, firewall, or IP camera into a relay that the operator can rent out or use to obscure follow-on intrusions against other networks.

Why the 18-Year-Old Bug List Matters

The breadth of the exploit arsenal, from CVE-2007-3010 to CVE-2025-55583, underlines how durable unpatched consumer and SMB networking gear remains in the wild. Devices that were end-of-life years ago are still reachable from the internet, and the botnet treats them as a fungible resource pool: each freshly enrolled node adds a clean residential or enterprise IP address that can bypass geo-restrictions, disguise attacks, or chain into further compromises. Fortinet's warning that the proxy functionality "significantly increases the value of an infected host to attackers" captures the economic logic: a single SOCKS5 node can be monetized repeatedly, which incentivizes patient reconnaissance and long dwell times rather than the smash-and-grab DDoS campaigns that defined the original Mirai era. For defenders, the practical takeaway is that patching the long tail of legacy CVEs on edge devices, not just the newest ones, is now a frontline concern.

Key points

  • Evooo1Bot is a Linux botnet, active since July 2026, that reuses Mirai's DDoS engine and adds SOCKS5 proxy, SSH brute-force, and credential-sniffing modules, per Fortinet FortiGuard Labs.
  • The botnet weaponizes a long list of known CVEs against routers, IP cameras, and industrial edge devices, ranging from a 2007 Alcatel flaw to 2025 D-Link and Telesquare command injection bugs.
  • After exploitation, a loader shell script is fetched from 91.92.40[.]118, fingerprints the CPU architecture, and clears Bash history to hide evidence.
  • The malware communicates with its C2 server over TCP port 443, blending encrypted traffic with ordinary HTTPS at the network perimeter.
  • The SOCKS5 proxy capability lets attackers monetize infected hosts as residential or enterprise proxy nodes, raising the per-device value beyond traditional DDoS botnets.
The Upside

Public disclosure of the full CVE list, the loader URL, and the C2 port gives defenders a concrete checklist to hunt for and patch affected devices. Greater visibility into the proxy-as-a-service business model may also pressure proxy brokers and abuse desks to block the IP ranges Evooo1Bot leans on.

The Downside

With SOCKS5 nodes rentable on residential and enterprise proxy markets, the operators have a durable monetization path that survives takedowns of individual C2 servers. The reliance on CVEs as old as 2007 means large pools of unpatched devices will likely remain available for years, and the inclusion of Kubernetes and Confluence exploits hints at lateral movement beyond the edge-device layer.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritylinuxiotbotnetmalware

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Aug 17, 2026

Source

thehackernews.com

Share

Topics

securitylinuxiotbotnetmalware

Related

More from this desk

Aug 17·bleepingcomputer.com

French tax authority data breach affects 678,000 individuals

The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals.

Aug 17·bleepingcomputer.com

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft is developing a patch for "ShieldBreak," a new zero-day privilege escalation vulnerability in Defender, disclosed by security researcher "Nightmare Eclipse." This flaw bypasses a previous Defender vulnerability, RoguePlanet, allowing local attackers to gain SYST…

Aug 17·thehackernews.com

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

A suspected Chinese-speaking APT is mass-exploiting a critical Broadcom VMware vCenter directory-traversal flaw (CVE-2026-59310, CVSS 9.8) to plant backdoors and stage ransomware across 361 victims in 47 countries.

Aug 16·bleepingcomputer.com

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal disclosed a data breach affecting 39,798 customers after an order-tracking flaw was exploited, with stolen data now being sold on a cybercrime forum.