Fortinet’s FortiGuard Labs has uncovered Evooo1Bot, a previously undocumented Linux botnet that has been active since July 2026 and turns internet-facing devices into criminal proxies.
Built on Mirai’s leaked DDoS engine, the malware layers in encrypted command-and-control traffic, an SSH brute-force scanner, a credential harvester, and a SOCKS relay module.
Initial access comes from exploiting known flaws in edge gear, including CVE-2021-36260 in Hikvision cameras, CVE-2022-26134 in Atlassian Confluence, and router bugs from NETGEAR (CVE-2016-6277), Tenda (CVE-2020-10987), D-Link, and Telesquare.
Successful exploitation runs a loader shell script that fetches an architecture-compatible bot binary. Operators can install persistence, update or kill the bot, transfer files, open an interactive shell, and intercept HTTP Basic Authorization and Cookie headers.
Once the proxy module runs, a compromised router, firewall, or camera becomes a SOCKS5 relay. That lets operators route malicious traffic through victim IPs, sidestep geographic blocks, and tunnel into internal networks. Fortinet notes the feature makes a single infected box far more valuable to an operator.
Defenders should inventory exposed routers, cameras, and Confluence instances, patch known CVEs, and watch for outbound connections to unknown staging hosts.
