GKRootWire
Cloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping AgentsCloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping Agents
Security

New Mirai-Based Botnet Evooo1Bot Hijacks Routers for Proxy Traffic

A modular Linux malware strain is quietly converting exposed gateway devices into SOCKS5 relay nodes for anonymized traffic.

Researchers have identified a new botnet called Evooo1Bot that builds on the leaked Mirai codebase but adds a twist: rather than just launching DDoS attacks, it's designed to turn compromised routers and other internet-facing gateway devices into SOCKS5 proxy relays.

Once infected, a device silently forwards traffic on behalf of whoever controls the botnet, letting attackers route malicious activity through thousands of residential and small-business IP addresses. This makes the traffic harder to block or trace back to its true origin.

The malware's modular architecture lets operators push updates and new capabilities to infected devices remotely, suggesting the botnet is still being actively developed and could expand its feature set over time.

Why it matters: Proxy botnets like this are increasingly valuable to criminals precisely because they blend malicious traffic in with real home and office IP addresses, defeating IP-reputation-based defenses. Admins should assume any unpatched, internet-exposed router is a target, not just for disruption but for quiet, long-term abuse as someone else's exit node.

Sources: BleepingComputer