A new Linux botnet called Evooo1Bot is targeting internet-facing gateway devices and converting them into SOCKS5 traffic relays, according to BleepingComputer, which cites research from Fortinet. The malware is described as Mirai-based, but with a broader modular toolset than the original leaked Mirai codebase. BleepingComputer reports that Evooo1Bot has been active since at least July against devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link across multiple regions. The attacks rely on known vulnerabilities rather than a newly disclosed flaw, based on the provided report. Fortinet researchers, as quoted by BleepingComputer, said the malware reuses Mirai’s distributed denial-of-service engine while extending it with encrypted command-and-control communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an exploit set aimed at multiple known vulnerabilities. In practical terms, the infected device is not only a DDoS node; it can also become infrastructure for relaying traffic and probing additional systems. The newer builds are broader still. BleepingComputer reports that a separate exploitation module targets Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. Fortinet also noted that some embedded exploits are not implemented correctly, which can cause exploitation attempts to fail. When an exploit works, the attack chain downloads one of 12 malware builds matched to the compromised system’s central processing unit architecture, according to the report. The script then clears Bash history in an attempt to remove signs of the intrusion. Evooo1Bot also performs checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before it runs. Persistence is handled through multiple Linux startup paths, including systemd, SysV init, shell profiles, and rc.local, with a cron job trying to re-download the payload every five minutes. The malware also gives operators an interactive shell for direct control and includes commands for uploading and downloading files. The relay function is central to why this botnet matters. BleepingComputer reports that Evooo1Bot’s SOCKS5 module supports both direct listening and reverse-relay modes, allowing operators to route traffic through compromised devices. Fortinet said proxy sessions run independently and multiple sessions can operate at once, creating the possibility of monetization through residential proxy services if the botnet becomes large enough. The malware’s credential sniffer watches /proc/net/tcp and attempts to capture HTTP Basic Authentication and Cookie headers, according to the report. Its SSH scanner uses 150 username-and-password combinations for enterprise-oriented accounts and performs post-login checks intended to avoid honeypots. Evooo1Bot also retains Mirai’s DDoS role. BleepingComputer reports that its DDoS module supports 16 flood methods, including UDP, DNS, SYN, ACK, GRE, fragmented TCP, and an HTTP flood mode with customizable requests. The recommended defenses in the report are conventional but important: keep internet-of-things firmware updated, replace default administrator credentials, disable remote access panels where possible, and retire devices once vendors stop supporting them. Who benefits: Attackers benefit if compromised devices can be used to conceal traffic, run multiple proxy sessions, or support DDoS activity. Fortinet also said the relay capability could support monetization through residential proxy services if the botnet grows large enough. Who's exposed: Owners of internet-facing gateway devices from the reported target set are exposed if they run vulnerable firmware or weak/default credentials. Organizations with remote access panels enabled on unsupported or poorly maintained devices are particularly at risk based on the report’s defensive guidance.