Skip to main content
LiMP VPN
All news

Evooo1Bot Botnet Turns Your Router Into a Hacker Proxy

Evooo1Bot Botnet Turns Your Router Into a Hacker Proxy

In short: Fortinet's FortiGuard Labs disclosed Evooo1Bot, a new Linux botnet active since at least July 2026. Built on Mirai source code, it silently infects home routers, IP cameras, and firewalls — then converts them into SOCKS5 proxies that relay criminal traffic and DDoS attacks, all while the device continues to function normally. Targets include popular brands such as NETGEAR, Tenda, D-Link, and Alcatel.

What Is Evooo1Bot and How Does It Infect Devices

On August 17, 2026, Fortinet FortiGuard Labs published a detailed analysis of Evooo1Bot — a previously undocumented Linux botnet built on the publicly leaked Mirai source code. The authors significantly extended the original framework, adding a SOCKS5 proxy module, an SSH brute-force scanner, a credential sniffer, encrypted C2 communications, and 16 DDoS attack methods.

Initial infection relies on known, publicly disclosed vulnerabilities in device firmware — CVEs that manufacturers have already patched but that many home and small-office networks have never applied. Once a device is compromised, Evooo1Bot establishes persistence, connects to the C2 server, and opens TCP port 1080 — the default SOCKS5 port — turning the device into a transparent relay for criminal traffic.

Protecting the traffic on your personal devices — for example, with LiMP VPN — creates an encrypted tunnel that keeps your connections private even on a compromised network. Protecting the router itself from infection, however, requires firmware updates: these are separate security layers.

Why Criminals Want Your Router

The operators are not after your personal data directly — they want your IP address and bandwidth. A network of compromised residential devices is a valuable criminal commodity:

  • Attack camouflage: DDoS traffic originating from thousands of residential IP addresses bypasses reputation-based filters that block known data-center ranges.
  • Proxy access sales: Evooo1Bot operators sell node access on underground markets. Residential proxy slots fetch $0.10–$3 per hour; a botnet of thousands of nodes generates steady revenue.
  • Credential harvesting: the embedded credential sniffer intercepts authentication data from traffic passing through the infected device.
  • DDoS-for-hire: 16 attack methods (UDP, DNS, SYN, GRE, fragmented TCP) make the botnet suitable for renting out to perform targeted attacks.

For you as a device owner, the risks are concrete: your IP address appears in databases of malicious infrastructure, your bandwidth is consumed without consent, and your ISP may suspend or investigate your connection for outbound malicious traffic.

Which Devices Are at Risk

According to Fortinet, Evooo1Bot targets equipment from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link — among the most common brands in home and small-office networks worldwide. The threat extends beyond routers to IP surveillance cameras, industrial gateways, and any Linux-based network device exposed to the internet.

What these devices share: they are always online, rarely updated, and almost never checked for signs of compromise. Critically, the vulnerabilities Evooo1Bot exploits are already patched. The problem is not that fixes are unavailable — it is that they are not applied.

Signs Your Device May Be Infected

Evooo1Bot is designed to be inconspicuous. Still, there are indirect indicators worth checking:

  • Unexplained increase in outbound traffic, especially at night;
  • Unfamiliar open ports (e.g., TCP 1080) revealed by a port scan;
  • Unexplained slowdowns or connection instability;
  • Warnings from your ISP about suspicious outbound traffic.

You can check open ports through the router's web interface. The most reliable way to verify a device is clean: factory reset followed by a firmware update to the latest available version.

How to Protect Your Network

Fortinet's recommendations are straightforward but routinely ignored:

  • Update firmware on all network devices. Known, patchable vulnerabilities are Evooo1Bot's only entry point. Check your router's admin interface for pending firmware updates.
  • Change default credentials. Many devices ship with admin/admin or admin/1234. The botnet's SSH brute-forcer tests these combinations first.
  • Disable remote management from the internet if you do not need it. Most home users do not.
  • Segment IoT devices into a separate guest Wi-Fi network. An infected camera should not have access to your phone or laptop.
  • Encrypt your personal device traffic. LiMP VPN creates an encrypted tunnel between your device and our servers — even if an attacker has partial network access, your traffic contents remain unreadable. See our protection features for more. Note: a VPN on your phone does not protect the router itself from infection — firmware updates do that.

Sources

Evooo1Bot Botnet Turns Your Router Into a Hacker Proxy