GKRootWire
AI Google Adds 'Preferred Source' Button to Help Publishers Fight AI Traffic LossesGadgets Linkdaze Launches a Smart Calendar Aimed at Running Your Whole HouseholdSecurity Popular Rust Crate arrayref Hijacked to Spread Infostealer MalwareCloud & Sysadmin GitHub Details Cause of August 17 Outage, Outlines Reliability FixesDev Tools Show HN: 'Huzzah' Proposes a Fresh Take on AI-Assisted CodingCloud & Sysadmin The Weird Science of Cooling Data Centers With UrineAI Google Adds 'Preferred Source' Button to Help Publishers Fight AI Traffic LossesGadgets Linkdaze Launches a Smart Calendar Aimed at Running Your Whole HouseholdSecurity Popular Rust Crate arrayref Hijacked to Spread Infostealer MalwareCloud & Sysadmin GitHub Details Cause of August 17 Outage, Outlines Reliability FixesDev Tools Show HN: 'Huzzah' Proposes a Fresh Take on AI-Assisted CodingCloud & Sysadmin The Weird Science of Cooling Data Centers With Urine
Security

New Mirai-Based Botnet Evooo1Bot Hijacks Routers for Proxy Traffic

A modular Linux malware strain is quietly converting exposed gateway devices into SOCKS5 relay nodes for anonymized traffic.

Researchers have identified a new botnet called Evooo1Bot that builds on the leaked Mirai codebase but adds a twist: rather than just launching DDoS attacks, it's designed to turn compromised routers and other internet-facing gateway devices into SOCKS5 proxy relays.

Once infected, a device silently forwards traffic on behalf of whoever controls the botnet, letting attackers route malicious activity through thousands of residential and small-business IP addresses. This makes the traffic harder to block or trace back to its true origin.

The malware's modular architecture lets operators push updates and new capabilities to infected devices remotely, suggesting the botnet is still being actively developed and could expand its feature set over time.

Why it matters: Proxy botnets like this are increasingly valuable to criminals precisely because they blend malicious traffic in with real home and office IP addresses, defeating IP-reputation-based defenses. Admins should assume any unpatched, internet-exposed router is a target, not just for disruption but for quiet, long-term abuse as someone else's exit node.

Sources: BleepingComputer