> Back to All Posts

Evooo1Bot Botnet Hijacks Routers to Relay Criminal Traffic

Evooo1Bot botnet

A new strain of Linux malware has been turning routers into relay points for criminal traffic. Researchers call the threat Evooo1Bot. The Evooo1Bot botnet has been active since at least July. It hunts for internet-facing gateway devices. Then it turns each one into a SOCKS5 proxy node.

The owner keeps browsing as normal. Meanwhile, someone else’s traffic leaves the same line, under the same home IP address. That single design choice makes this campaign matter far more to home users than a plain DDoS threat.

What the Evooo1Bot botnet does once it lands

The malware borrows its DDoS engine from Mirai, the botnet family whose code leaked years ago. Everything else, however, is new. The Evooo1Bot botnet ships as a set of modules, so attackers can pick which parts to run on each device.

Those parts cover a lot of ground. There is an SSH brute-force scanner, a SOCKS5 relay, and a sniffer that grabs logins. A bundle of exploits targets known flaws in older gear. An interactive shell hands attackers direct control of a hacked system. File transfer commands let them move data in and out.

The devices under attack

Since July, the Evooo1Bot botnet has hit gear from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. Infections also turn up across several regions, not one country.

Newer builds cast a wider net. They add exploits for Hikvision cameras, Zyxel firewalls, TP-Link routers, and D-Link NAS units. Others target Atlassian Confluence, WSO2 products, Kubernetes ingress-nginx, and old PHP-CGI setups. Still, not all of them work. Several fail outright because the crew put them together in a rush.

When an exploit does land, a script checks the chip type of the host. It then pulls the right build from twelve options. After that, the script wipes Bash history to erase the trail.

Built to stay hidden

The Evooo1Bot botnet runs a long list of checks before it does anything. It looks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots. If the setup looks like a lab, the malware holds back.

Control traffic moves in encrypted form over port 443. Normal HTTPS browsing uses that same port. So the activity blends into everyday noise, and few home users would ever spot it.

The malware digs in through four routes: systemd, SysV init, shell profiles, and rc.local. A cron job also tries to pull the payload again every five minutes. Because of those backups, deleting one file rarely clears the problem.

Why the proxy function matters most

The relay part of the Evooo1Bot botnet is the piece that should worry home users. The SOCKS5 module works in direct listening and reverse-relay modes. Sessions run on their own, so attackers can open several at once.

There is a clear business model behind that design. Once a botnet grows large enough, its crew can rent out infected devices through residential proxy services. Buyers then get IP addresses that look like real homes, because they are real homes.

The fallout lands on the device owner. Fraud, credential stuffing, scraping, and account takeovers all leave from a home line. Blocklist entries, endless CAPTCHAs, and service bans follow. Some victims only notice when a bank or a streaming app starts flagging their connection.

This is also why cheap and free proxy tools deserve suspicion. Many of them source their exit nodes from exactly this kind of hijack.

Credential theft on your own network

The sniffer inside the Evooo1Bot botnet watches /proc/net/tcp for useful data. It tries to grab HTTP Basic Auth and cookie headers. So any login sent through an infected gateway without encryption becomes readable.

The SSH scanner adds another problem. It cycles through 150 username and password pairs aimed at business accounts. It then runs post-login checks to dodge honeypots. Weak or reused SSH logins open a direct path deeper into a network.

How to keep the Evooo1Bot botnet off your hardware

Router security rarely gets much notice until something breaks. A few habits close most of the doors this campaign relies on.

Lock down the device

Install firmware updates as soon as vendors release them. Nearly every infection here starts with a flaw that already has a patch. Swap default admin logins for long, unique passwords. Switch off remote management panels unless you truly need them. Retire hardware once the maker stops sending security fixes, because those devices never get another one.

Encrypt what leaves your devices

A trusted VPN encrypts your traffic before it reaches the router. So a sniffer on a hijacked gateway sees scrambled data instead of logins and session cookies. That will not remove an infection. It does strip away most of the value in watching your line.

Pick a provider with a no-logs claim that outside auditors have checked. Free proxy tools and unknown browser add-ons belong nowhere near this threat.

Final Thoughts

The Evooo1Bot botnet fits a wider shift in how attackers value hijacked hardware. Raw DDoS power still pays, but proxy access pays better and draws far less notice. A router that relays someone else’s traffic looks perfectly healthy from the inside.

That quiet payoff is why the Evooo1Bot botnet matters beyond security teams. Home networks now sit on the same target list as company servers. Patch the gateway, kill the default passwords, and encrypt what you send. Those three steps take away most of what this campaign hunts for.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.