Evooo1Bot botnet converts routers into covert relay infrastructure
Mirai-based malware targets internet-facing gateways, enslaving them as SOCKS5 proxies to obscure malicious traffic and enable credential theft.
A modular Linux botnet named Evooo1Bot is compromising internet-facing routers and gateway devices, converting them into SOCKS5 traffic relay nodes. The malware, built on the Mirai framework, allows operators to route malicious traffic through infected devices, obscuring the origin of attacks and credential-harvesting operations.
The botnet's modular architecture enables operators to deploy additional capabilities post-compromise. Once a device is infected, it becomes part of a distributed proxy network that can be leased or used internally for further intrusions. The use of compromised home and small-office routers as relay infrastructure complicates attribution and evades network-based detection.
Evooo1Bot joins a growing class of IoT-focused botnets exploiting weak or default credentials on edge devices. The Mirai lineage indicates likely use of known exploits and brute-force techniques against Telnet and SSH services. Operators gain persistent access to devices that typically lack robust logging or endpoint protection, making detection and remediation difficult for device owners.
- 01Organizations face increased risk of credential theft routed through trusted residential IP space.
- 02ISPs and network defenders lose visibility into attack origins when traffic transits compromised routers.
- 03Device manufacturers remain under pressure to enforce secure-by-default configurations and timely patching.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.