A New Mirai-Based Botnet Is Turning Routers Into Proxy Nodes
Security researchers have identified a new modular Linux botnet called Evooo1Bot that is compromising internet-facing gateway devices such as routers and turning them into SOCKS5 traffic relay nodes. SOCKS5 is a proxy protocol that lets one device forward internet traffic on behalf of another, and attackers commonly abuse it to route malicious traffic through victim devices to obscure the true source. According to FortiGuard Labs, which analyzed the malware, Evooo1Bot is built on the long-running Mirai codebase and adds multiple functions beyond simple denial-of-service attacks, including SSH brute-force capability and exploitation of known CVEs (Common Vulnerabilities and Exposures, the standard identifiers used to track publicly disclosed software flaws) to gain initial access to devices.
The botnet was first publicly detailed in reporting this week, with FortiGuard Labs' technical writeup describing its modular design: separate components handle distributed denial-of-service (DDoS) flooding, credential-guessing attacks against SSH services, and the SOCKS5 proxy relay function that lets operators sell or rent access to compromised devices as anonymized traffic relays. Mirai, the malware family Evooo1Bot descends from, first became widely known in 2016 after it was used to build a botnet of hundreds of thousands of IoT devices that knocked major internet services offline. Its source code has been public for years, and it has since spawned dozens of variants targeting routers, cameras, and other internet-facing embedded devices that often run stripped-down Linux operating systems with limited built-in security tooling.
What makes gateway devices like routers attractive targets is straightforward: they sit at the edge of a network, are almost always internet-facing by design, frequently run outdated firmware, and are rarely monitored the way servers or laptops are. Once compromised, a router can be silently repurposed for DDoS attacks, credential-stuffing campaigns against other targets, or as a relay that hides an attacker's real IP address behind a legitimate residential or business connection, a technique that has become increasingly valuable to threat actors looking to evade IP-based blocklists and geographic filtering used by fraud-detection and threat-intelligence systems.
Key Takeaway
Evooo1Bot exploits known CVEs and weak SSH credentials on internet-facing routers and gateway devices, then turns them into SOCKS5 proxy relays for DDoS and other malicious traffic. If your business uses a router, firewall appliance, or VPN gateway that has not been patched or still uses default credentials, it may be exposed.
What This Means For Your Business
For healthcare practices, tax professionals, and small businesses, this development is a reminder that network edge devices, routers, firewalls, VPN appliances, and similar gateway hardware, are not "set and forget" equipment. They are full participants in your attack surface, and a compromised router can quietly implicate your organization's IP address in attacks against third parties, or serve as a foothold for lateral movement into internal systems. For practices handling protected health information or financial data, a compromised gateway device sitting between your network and the internet is a particularly sensitive point of failure, since it can potentially observe or redirect traffic before it ever reaches your endpoint security controls.
The practical defense against Mirai-family botnets like Evooo1Bot has not changed much since 2016, but it remains widely under-implemented: patch internet-facing device firmware promptly, since these botnets specifically hunt for known, already-disclosed CVEs rather than novel zero-days; replace default or weak administrative credentials on every router, firewall, and gateway device, since automated SSH brute-force is one of the malware's stated infection paths; and disable remote administration interfaces (SSH, Telnet, web admin panels) on the WAN-facing side of these devices unless there is a specific, documented business need for them.
Beyond individual device hardening, organizations should periodically check whether their public IP addresses appear on threat-intelligence blocklists, which can be an early indicator that a device on the network is being used as a relay or attack node without staff awareness. Reviewing router and firewall logs for unexpected outbound connections, unusually high traffic volumes during off-hours, or connections to unfamiliar geographic regions can also surface compromise before it escalates. For practices under HIPAA or similar regulatory frameworks, a compromised gateway device that has been silently relaying attacker traffic could complicate incident documentation and breach-notification assessments even if patient data itself was never directly accessed, so treating edge-device integrity as part of your risk management program, not just an IT convenience issue, is the more defensible posture.
Finally, this case underscores a broader point Bellator Cyber Guard has emphasized before: the devices least visible to your team are often the most attractive to attackers precisely because they are least visible. Asset inventories for small businesses should explicitly include every internet-facing router, firewall, and gateway appliance, with an owner responsible for firmware updates and credential hygiene on each one, rather than assuming the device "just works" once it is plugged in.
People also look for
Keep exploring Ransomware & recovery
Reduce the chance of an infection, limit its reach, and make recovery possible without improvising under pressure.
- Common question: what is ransomwareUnderstand how ransomware worksLearn how attacks begin, spread, encrypt data, and pressure victims.
- Common question: ransomware protection for small businessProtect a small business from ransomwareCoordinate endpoint detection, access control, backups, and response planning.
- Common question: 3-2-1 backup strategyBuild recoverable backupsKeep multiple protected copies and verify that important systems can actually be restored.
- Common question: ransomware recovery planUse the ransomware protection guidePlan prevention, containment, restoration, and communication before an incident.
- Common question: healthcare ransomware preventionReduce ransomware risk in healthcareProtect clinical operations, patient records, and recovery capability.
Learn first. Decide when you are ready.
Keep learning—or apply this to your situation
Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.



