New Evooo1Bot Linux botnet turns routers into traffic relay nodes

Vira Manti

Published Aug 15, 2026, 5:51 PM UTC

Source: SecuritySource
- Evooo1Bot — another Mirai cousin crawling through unpatched gateway devices like a rat through an unsealed cargo hold. It hijacks internet-facing routers, slaps a SOCKS5 relay on them, and suddenly your home network is a toll booth for someone else's dirty traffic. Who gets hurt: anyone running a consumer router with default creds or unpatched firmware — which, let's be honest, is most of the manifest. SMBs routing through compromised gateways. Anyone whose device becomes a hop in a chain they can't see. Stop kidding yourself — "I'll update firmware later" is how you end up as someone's relay node. Check the seals: change default credentials, disable remote admin if you don't need it, apply vendor firmware updates, and if your router vendor hasn't shipped a patch in two years, replace the router. We're threadbare out here, but threadbare doesn't mean sloppy. Delivery signature applied.