Mirai Botnet Evooo1Bot Exploits IoT Edge Devices for Covert Traffic

www.news4hackers.com-mirai-botnet-evooo1bot-exploits-iot-edge-devices-for-covert-traffic-mirai-botnet-evooo1bot-exploits-iot-edge-devices-for-covert-traffic

A modular Linux malware strain, Evooo1Bot, is exploiting routers and IoT devices globally, repurposing them for DDoS attacks and proxy relays.

Botnet Architecture

Evooo1Bot is a sophisticated malware strain that transforms internet-facing networking equipment into covert infrastructure for malicious activities. Researchers have uncovered its botnet architecture, which repurposes edge hardware as encrypted proxy relays and DDoS tools. The malware was first detected by Fortinet’s FortiGuard Labs in mid-2026 and represents an evolution from traditional Linux-based threats.

DDoS Capabilities

The malware’s DDoS capabilities are derived from the 2016 Mirai source code but include advanced features such as proxy routing, credential harvesting, and honeypot evasion. These enhancements allow compromised edge devices to function as commercial-grade proxy relays, enabling anonymous traffic routing and network infiltration.

Proxy Server Functionality

The botnet’s primary function involves converting routers and gateway devices into SOCKS5 proxy servers. This allows attackers to route malicious traffic through compromised nodes, obscuring their origins and bypassing regional network restrictions. The proxies can also act as entry points for deeper network exploitation, leveraging legitimate IP addresses to evade detection.

Persistence Mechanisms

Evooo1Bot employs a multi-stage persistence mechanism to maintain long-term control over infected systems. It establishes persistence through systemd service units, SysV initialization scripts, and cron job schedules. This complexity complicates remediation efforts for administrators, as the malware can maintain presence across multiple system layers.

Exploitation Strategies

The botnet’s expansion strategy relies on remote code execution (RCE) and command injection exploits targeting hardware from vendors including D-Link, NETGEAR, Tenda, Telesquare, and Alcatel. In addition to exploiting known vulnerabilities, Evooo1Bot includes an automated SSH brute-force scanner with pre- and post-login checks to identify honeypots such as Cowrie or HonSSH.

Command-and-Control Communications

Evooo1Bot obfuscates C2 communications using layered encryption protocols, including AES-256-CTR, ChaCha20, and XOR algorithms. This encryption blends C2 traffic with standard HTTPS traffic on port 443, enabling the botnet to evade perimeter firewall detection.

Risks in India

The proliferation of proxy-enabled botnets poses significant risks for countries with extensive IoT adoption, such as India. Unpatched residential and small-office routers remain vulnerable, creating potential entry points for cyberattacks. As India advances its Digital India initiative, compromised edge devices threaten supply chain security.

Authorities such as the Indian Computer Emergency Response Team (CERT-In) and the National Cyber Security Coordinator have emphasized the dangers of unpatched hardware, noting that such devices are frequently used to mask financial fraud or launch cyberattacks.

Recommendations

Recommendations to mitigate the threat include enforcing strict access controls, auditing edge device configurations, disabling exposed management ports, and applying firmware updates from manufacturers. Proactive security measures and continuous monitoring of network endpoints are critical to addressing the evolving threat landscape.

Conclusion

The emergence of Evooo1Bot underscores the growing sophistication of malware targeting edge infrastructure. Its ability to repurpose legitimate hardware for malicious purposes highlights the need for vigilance, regular updates, and robust security protocols to protect critical network assets.



About Author

en_USEnglish