New Mirai-Based Botnet Evooo1Bot Hijacks Routers for Proxy Traffic
Researchers have identified a new botnet called Evooo1Bot that builds on the leaked Mirai codebase but adds a twist: rather than just launching DDoS attacks, it's designed to turn compromised routers and other internet-facing gateway devices into SOCKS5 proxy relays.
Once infected, a device silently forwards traffic on behalf of whoever controls the botnet, letting attackers route malicious activity through thousands of residential and small-business IP addresses. This makes the traffic harder to block or trace back to its true origin.
The malware's modular architecture lets operators push updates and new capabilities to infected devices remotely, suggesting the botnet is still being actively developed and could expand its feature set over time.