Threat Intelligence

New Linux Botnet 'Evooo1Bot' Hijacks Vulnerable Devices for Proxy Networks

The Hacker News · 17 Aug 2026
Key Takeaway Regularly update and patch firmware on routers, firewalls, and other internet-facing devices to prevent them from being hijacked into botnets like Evooo1Bot.

Security researchers have identified a new botnet called Evooo1Bot that targets Linux-based, internet-connected devices such as routers, firewalls and other network 'edge' hardware. Built on the leaked source code of the notorious Mirai botnet, Evooo1Bot goes further than its predecessor by adding the ability to convert infected devices into SOCKS5 proxies, allowing attackers to route malicious traffic through unsuspecting businesses' networks.

By exploiting known, unpatched vulnerabilities in edge devices, the malware gains a foothold and can then be used for distributed denial-of-service (DDoS) attacks or as a hidden relay point for other criminal activity. Because many of these devices sit at the boundary of a company's network and are often overlooked in routine patching cycles, they present an attractive and persistent target for attackers.

For small and medium businesses, this development is a reminder that internet-facing equipment—not just laptops and servers—needs regular security attention. Devices left running outdated firmware are effectively an open door, and once compromised, they can be silently used to attack others or mask illegal traffic without the owner's knowledge.

botnet Linux malware network security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.