Evooo1Bot Linux Botnet Exploits Known Vulnerabilities to Create SOCKS5 Proxies

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Cybersecurity researchers have identified a new Linux botnet family named Evooo1Bot, which is based on the Mirai botnet source code and is capable of converting internet-facing devices into SOCKS proxies. This botnet has reportedly been active since July 2026, exploiting known vulnerabilities in publicly accessible devices to propagate the malware.

According to reporting by The Hacker News, the malware utilizes a DDoS engine derived from Mirai but enhances its functionality with features such as encrypted command-and-control (C2) communications, an SSH brute-force scanner, a SOCKS relay module, and a credential sniffer. It also includes an arsenal of exploits targeting multiple known vulnerabilities.

The botnet exploits several vulnerabilities, including:

  • CVE-2007-3010 – Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
  • CVE-2016-6277 – NETGEAR Multiple Routers Remote Code Execution Vulnerability
  • CVE-2018-14558 – Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
  • CVE-2019-14931 – Mitsubishi Electric Europe B.V. ME-RTU devices remote Command Injection vulnerability
  • CVE-2020-10987 – Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
  • CVE-2021-46422 – Telesquare SDT-CW3B1 Command Injection vulnerability
  • CVE-2022-37055 – D-Link Routers Buffer Overflow Vulnerability
  • CVE-2024-29269 – Telesquare TLR-2005KSH Command Injection Vulnerability
  • CVE-2025-10123 – D-Link DIR-823X Command Injection Vulnerability
  • CVE-2025-55583 – D-Link DIR-868L B1 router Command Injection Vulnerability

Once a device is compromised, a loader shell script is executed, which retrieves the botnet binary from an external server. This binary then establishes encrypted communications with a C2 server, allowing the attacker to issue commands and control the infected device.

The botnet’s capabilities include launching DDoS attacks, intercepting HTTP Basic Authorization and Cookie headers, and transforming compromised devices into SOCKS5 proxies. This proxy functionality allows attackers to disguise their malicious traffic and potentially access internal networks through compromised machines.

Fortinet highlighted that the ability to use infected hosts as proxies significantly increases their value to attackers, enabling them to build a distributed proxy infrastructure for anonymous traffic forwarding or monetization.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...