New Linux Botnet 'Evooo1Bot' Hijacks Vulnerable Devices for Proxy Networks
Security researchers have identified a new botnet called Evooo1Bot that targets Linux-based, internet-connected devices such as routers, firewalls and other network 'edge' hardware. Built on the leaked source code of the notorious Mirai botnet, Evooo1Bot goes further than its predecessor by adding the ability to convert infected devices into SOCKS5 proxies, allowing attackers to route malicious traffic through unsuspecting businesses' networks.
By exploiting known, unpatched vulnerabilities in edge devices, the malware gains a foothold and can then be used for distributed denial-of-service (DDoS) attacks or as a hidden relay point for other criminal activity. Because many of these devices sit at the boundary of a company's network and are often overlooked in routine patching cycles, they present an attractive and persistent target for attackers.
For small and medium businesses, this development is a reminder that internet-facing equipment—not just laptops and servers—needs regular security attention. Devices left running outdated firmware are effectively an open door, and once compromised, they can be silently used to attack others or mask illegal traffic without the owner's knowledge.