Daily Security Intel

Archives
Log in
Subscribe
August 16, 2026

[SecurityIntel] 16 Aug | Evooo1Bot Botnet Recruits Routers as SOCKS5 Relays

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, August 16, 2026

INTEL CONFIDENCE  76%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Evooo1Bot Botnet Recruits Routers as SOCKS5 Relays

CRITICAL

5

C2 IPs

40

OTX IOCs

1

ARTICLES

■ ANALYST TLDR

A new Mirai-based modular Linux botnet named "Evooo1Bot" is actively targeting internet-facing gateway devices and routers. The malware compromises these systems to convert them into SOCKS5 traffic relay nodes, allowing threat actors to route malicious traffic through legitimate IP addresses. Organizations must secure edge devices, disable external management interfaces, and monitor for anomalous outbound proxy traffic.

■ CRITICAL STORIES

HIGH#1

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new modular Mirai-based botnet, Evooo1Bot, is actively compromising internet-facing gateway devices. By converting these edge devices into SOCKS5 traffic relay nodes, threat actors can route malicious traffic through legitimate residential or corporate IPs, complicating attribution and bypassing IP-based defenses.

■ CVEs IDENTIFIED

[CVE-TBD]

Linux gateway devices / routers — Remote Code Execution leading to botnet recruitment

Critical

■ THREAT ACTORS

Evooo1Bot Operators

Cybercrime

Deploying Evooo1Bot malware to build SOCKS5 proxy networks via compromised routers

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used to compromise internet-facing gateway devices
T1090
Proxy | Converting compromised routers into SOCKS5 traffic relay nodes
T1033
System Owner/User Discovery | Identifying gateway device details during infection

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Linux gateway devices / Routers — Suspected RCE/unauthorized access vulnerabilities exploited by Evooo1Bot to recruit devices into botnet — BC

■ RECOMMENDED ACTIONS TODAY

1[P1] Audit all internet-facing gateway devices and routers for exposed management interfaces (e.g., SSH, Telnet, Web UI) and disable external access.
2[P1] Update firmware on all Linux-based gateway devices and routers to the latest vendor-supported versions to mitigate potential [CVE-TBD] exploitation vectors.
3[P2] Implement strict network egress filtering to detect and block unauthorized SOCKS5 proxy traffic originating from edge routers.
4[P3] Monitor system logs on edge devices for anomalous reboot cycles or unauthorized configuration changes indicative of Evooo1Bot infection.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 15 Aug | SAP Commerce Cloud and GeoServer Under Active Exploitation
Powered by Buttondown, the easiest way to start and grow your newsletter.