By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Evooo1Bot Linux Botnet Exploits Flaws for Proxy Functionality

Cybersecurity researchers have identified a new Linux botnet family, dubbed Evooo1Bot, which utilizes the source code of the well-known Mirai botnet to gain its primary functionalities. This botnet is specifically designed to convert internet-facing devices into SOCKS proxies, enabling malicious actors to route traffic through compromised systems. The malware reuses the distributed denial-of-service (DDoS) engine from the publicly leaked Mirai source code but significantly expands upon the original framework with a variety of new capabilities.
Evooo1Bot's functionality extends beyond its DDoS origins. Researchers noted that the botnet is capable of performing brute-force attacks against Telnet and SSH services, a common tactic for gaining initial access to internet-connected devices. Once a device is compromised, Evooo1Bot can be used to establish SOCKS proxies. A SOCKS proxy is a type of proxy server that provides a way to route network packets between a client and a server through a proxy server. This allows the botnet operators to mask their origin and conduct further malicious activities, such as launching attacks or accessing restricted networks, from the compromised devices.
The researchers highlighted that Evooo1Bot exploits known vulnerabilities and weak credentials to infiltrate devices. This reliance on common attack vectors means that many internet-facing devices, particularly those with default or weak passwords and unpatched software, are susceptible to infection. The botnet's ability to leverage the Mirai codebase suggests a lineage that is familiar with large-scale botnet operations, potentially indicating a sophisticated threat actor or a group building upon existing, proven infrastructure. The use of SOCKS proxies is a critical component, as it allows for a wide range of illicit activities to be conducted with a reduced risk of attribution to the actual perpetrators.
The discovery of Evooo1Bot underscores the persistent threat posed by botnets that evolve by incorporating and adapting existing malware frameworks. The fact that it builds upon Mirai, a botnet that gained notoriety for its massive DDoS attacks, suggests a potential for significant disruption. The transformation of everyday internet-connected devices, such as routers, IoT devices, and servers, into proxies creates a distributed network that can be difficult to track and dismantle. Security professionals are advised to ensure that their internet-facing devices are secured with strong, unique passwords, have their firmware updated regularly, and are protected by robust network security measures to mitigate the risk of compromise by botnets like Evooo1Bot.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.