New Evooo1Bot Linux botnet turns routers into traffic relay nodes

New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Evooo1Bot is a new Mirai-based modular Linux botnet that targets internet-facing gateway devices to turn them into SOCKS5 relay nodes while also enabling credential theft, SSH brute-forcing, and DDoS attacks. It has been observed exploiting multiple known vulnerabilities across devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, D-Link, and other platforms, with newer builds targeting Hikvision, Confluence, Zyxel, TP-Link, WSO2, Kubernetes ingress-nginx, and PHP-CGI systems. #Evooo1Bot #Mirai #Alcatel #NETGEAR #Tenda #MitsubishiElectric #Telesquare #DLink #Hikvision #AtlassianConfluence #Zyxel #TPLink #WSO2 #Kubernetes #ingress-nginx #PHP-CGI

Keypoints

  • Evooo1Bot is a Mirai-based modular botnet for Linux devices.
  • It turns infected gateways into SOCKS5 traffic relay nodes.
  • It can steal credentials, brute-force SSH, and launch DDoS attacks.
  • It targets many devices and services by exploiting known vulnerabilities.
  • It uses encrypted C2, persistence methods, and anti-analysis checks to stay hidden.

Read More: https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/