Breaking News
Menu
Advertisement

Evooo1Bot: New Linux Botnet Hijacks Routers into Hidden SOCKS5 Proxies

Evooo1Bot: New Linux Botnet Hijacks Routers into Hidden SOCKS5 Proxies

A newly discovered Linux botnet named Evooo1Bot is actively hijacking internet-exposed routers and gateways, transforming them into hidden SOCKS5 proxies. Based on the notorious Mirai architecture, this modular malware goes beyond simple disruption, allowing attackers to silently harvest enterprise credentials and launch massive distributed denial-of-service (DDoS) attacks.

According to threat intelligence data revealed by Fortinet, the botnet has been operating actively since at least July. The malware specifically targets a wide range of networking equipment and edge devices, exploiting known vulnerabilities to guarantee system access.

Targeted Devices and Exploitation Tactics

Evooo1Bot focuses its initial compromise efforts on equipment from major brands, including Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. Researchers noted that recent versions of the threat have expanded their exploit modules to target an even broader attack surface.

The expanded target list now includes Hikvision cameras, WSO2 products, Atlassian Confluence, Zyxel firewalls, TP-Link routers, and D-Link NAS systems. Furthermore, the botnet actively scans for vulnerable installations of PHP-CGI and Kubernetes ingress-nginx.

However, the research team points out that not all embedded exploits are implemented correctly, frequently resulting in failed intrusion attempts. When an attack is successful, the script downloads one of 12 available software versions tailored to the target's processor architecture. It then immediately clears the Bash history to erase any trace of the operation.

Evasion, Persistence, and Credential Theft

Before executing its primary payload, Evooo1Bot performs extensive environmental checks to detect the presence of debuggers, security tools, sandboxes, virtual machines, containers, or honeypots. Communication with its command-and-control (C2) servers is fully encrypted over port 443.

Once securely installed on the device, the malware guarantees its persistence through multiple system mechanisms, including systemd, shell profiles, SysV init, and rc.local. It also establishes a cron job that attempts to re-download the core payload every 5 minutes.

To expand its impact, the botnet integrates a credential interceptor that actively monitors the following directory for HTTP basic authentication headers and cookies:

/proc/net/tcp

The malware also features a dedicated SSH module that tests 150 enterprise-focused username and password combinations, performing post-login verifications to avoid security traps.

SOCKS5 Proxy and DDoS Capabilities

The sheer range of Evooo1Bot's capabilities makes it highly stealthy and versatile. Its SOCKS5 module supports both relay and direct listening modes, offering attackers the ability to hide malicious traffic, bypass geographical restrictions, or pivot into internal networks. These proxy sessions operate independently and can be opened simultaneously, paving the way for attackers to monetize the access through residential proxy services.

When weaponized for disruption, the botnet's DDoS module is capable of unleashing 16 distinct flood methods. These include UDP, DNS, SYN, ACK, GRE, fragmented TCP, and custom HTTP requests, making it a formidable tool for taking down targeted infrastructure.

The Monetization of Edge Devices

The emergence of Evooo1Bot highlights a significant shift in how threat actors view compromised edge devices. While early Mirai variants were primarily focused on building massive DDoS armies, modern iterations are heavily optimized for silent monetization.

By integrating SOCKS5 proxy capabilities alongside aggressive credential harvesting, attackers are creating a dual-revenue stream. They can rent out the compromised routers as "clean" residential proxies to other cybercriminals, while simultaneously selling the intercepted enterprise credentials on dark web forums. This evolution means that an unpatched router is no longer just a participant in a botnet - it is an active surveillance node sitting at the edge of the corporate network.

Did you like this article?
Advertisement

Popular Searches