SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, August 16, 2026 INTEL CONFIDENCE 76% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Evooo1Bot Botnet Recruits Routers as SOCKS5 Relays | CRITICAL |
|
5 C2 IPs | 40 OTX IOCs | 1 ARTICLES |
|
■ ANALYST TLDR A new Mirai-based modular Linux botnet named "Evooo1Bot" is actively targeting internet-facing gateway devices and routers. The malware compromises these systems to convert them into SOCKS5 traffic relay nodes, allowing threat actors to route malicious traffic through legitimate IP addresses. Organizations must secure edge devices, disable external management interfaces, and monitor for anomalous outbound proxy traffic. |
|
■ CRITICAL STORIES New Evooo1Bot Linux botnet turns routers into traffic relay nodes A new modular Mirai-based botnet, Evooo1Bot, is actively compromising internet-facing gateway devices. By converting these edge devices into SOCKS5 traffic relay nodes, threat actors can route malicious traffic through legitimate residential or corporate IPs, complicating attribution and bypassing IP-based defenses. |
|
■ CVEs IDENTIFIED [CVE-TBD] Linux gateway devices / routers — Remote Code Execution leading to botnet recruitment |
|
■ THREAT ACTORS Evooo1Bot Operators | Cybercrime |
Deploying Evooo1Bot malware to build SOCKS5 proxy networks via compromised routers |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used to compromise internet-facing gateway devices |
| T1090 | | Proxy | Converting compromised routers into SOCKS5 traffic relay nodes |
| T1033 | | System Owner/User Discovery | Identifying gateway device details during infection |
|
■ PATCH PRIORITY Linux gateway devices / Routers — Suspected RCE/unauthorized access vulnerabilities exploited by Evooo1Bot to recruit devices into botnet — BC |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Audit all internet-facing gateway devices and routers for exposed management interfaces (e.g., SSH, Telnet, Web UI) and disable external access. |
| 2 | [P1] Update firmware on all Linux-based gateway devices and routers to the latest vendor-supported versions to mitigate potential [CVE-TBD] exploitation vectors. |
| 3 | [P2] Implement strict network egress filtering to detect and block unauthorized SOCKS5 proxy traffic originating from edge routers. |
| 4 | [P3] Monitor system logs on edge devices for anomalous reboot cycles or unauthorized configuration changes indicative of Evooo1Bot infection. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |