[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes-msvxt1jg":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"ffb33d6f-dece-4b25-837f-7f1c2d561689","New Evooo1Bot Linux botnet turns routers into traffic relay nodes","new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes-msvxt1jg","Evooo1Bot, a Mirai-based botnet, is actively compromising internet-facing routers and gateway devices by exploiting known vulnerabilities. Infected devices become SOCKS5 proxies for threat actors while also enabling credential theft, SSH brute-forcing, and DDoS attacks. Any organization with exposed network infrastructure is at risk.","high","advisory",[],[13,14,15,16,17],"Alcatel routers","NETGEAR routers","Tenda routers","Mitsubishi Electric devices","Telesquare devices","Immediately scan your network perimeter for internet-exposed routers and gateways. Prioritize patching known vulnerabilities in router firmware across all manufacturers. Block suspicious outbound SOCKS5 traffic (port 1080) and monitor for SSH brute-force attempts originating from internal devices.",[20],"fd1d38ab-b512-4b9f-bf5b-8aba70aadab5",null,[23],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes\u002F","archived","2026-08-18T15:05:41.185+00:00","2026-08-16T15:05:49.430398+00:00","2026-08-18T16:06:31.855004+00:00",[29],{"id":20,"title":6,"url":23}]