Back to advisories

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

Evooo1Bot, a Mirai-based botnet, is actively compromising internet-facing routers and gateway devices by exploiting known vulnerabilities. Infected devices become SOCKS5 proxies for threat actors while also enabling credential theft, SSH brute-forcing, and DDoS attacks. Any organization with exposed network infrastructure is at risk.

HIGHAdvisoryAug 16, 2026
Action required
Immediately scan your network perimeter for internet-exposed routers and gateways. Prioritize patching known vulnerabilities in router firmware across all manufacturers. Block suspicious outbound SOCKS5 traffic (port 1080) and monitor for SSH brute-force attempts originating from internal devices.
Affected products
Alcatel routersNETGEAR routersTenda routersMitsubishi Electric devicesTelesquare devices