Executive Summary
In August 2026, security researchers identified a new Mirai-based modular Linux botnet named Evooo1Bot, which has been actively targeting internet-facing gateway devices from manufacturers such as Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link. By exploiting known vulnerabilities, Evooo1Bot compromises these devices, transforming them into SOCKS5 traffic relay nodes. Beyond proxying capabilities, the malware exhibits functionalities including credential theft, SSH brute-forcing, and the execution of distributed denial-of-service (DDoS) attacks. Notably, Evooo1Bot employs encrypted command-and-control communications over port 443 and implements various persistence mechanisms to maintain control over infected systems.
The emergence of Evooo1Bot underscores a concerning trend in the evolution of botnet malware, where attackers are increasingly leveraging compromised IoT devices to facilitate anonymized malicious activities. This development highlights the critical need for organizations and individuals to proactively secure their networked devices by regularly updating firmware, changing default credentials, and disabling unnecessary remote access features to mitigate the risk of exploitation by such sophisticated threats.
Why This Matters Now
The rapid proliferation of Evooo1Bot demonstrates the escalating sophistication of botnet malware, emphasizing the urgency for enhanced security measures to protect IoT devices from being co-opted into malicious networks.
Attack Path Analysis
Evooo1Bot exploited known vulnerabilities in internet-facing devices to gain initial access, then escalated privileges by deploying malware tailored to the host's CPU architecture. It moved laterally by brute-forcing SSH credentials on other devices, established encrypted command and control channels over port 443, and exfiltrated data by capturing HTTP authentication headers. The botnet's impact included turning compromised devices into SOCKS5 proxies and launching DDoS attacks.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Evooo1Bot exploited known vulnerabilities in internet-facing devices from vendors like Alcatel, NETGEAR, and D-Link to gain initial access.
Related CVEs
CVE-2025-29635
CVSS 7.2A command injection vulnerability in D-Link DIR-823X series routers allows remote attackers to execute arbitrary commands.
Affected Products:
D-Link DIR-823X series routers – All versions up to discontinuation in 2025
Exploit Status:
exploited in the wildCVE-2025-24016
CVSS 9.9A deserialization vulnerability in Wazuh Server allows remote code execution on affected devices.
Affected Products:
Wazuh Wazuh Server – All versions prior to patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Password Guessing
Web Protocols
External Proxy
Process Injection
Valid Accounts
Network Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical exposure to Evooo1Bot targeting routers and network infrastructure, enabling traffic interception, credential theft, and potential service disruption across telecommunications networks.
Information Technology/IT
High risk from botnet exploitation of enterprise gateway devices, SSH brute-forcing, and SOCKS5 proxy abuse compromising network security and client infrastructure.
Financial Services
Severe threat from credential sniffing capabilities targeting HTTP authentication, potential PCI compliance violations, and lateral movement risks through compromised network devices.
Health Care / Life Sciences
Significant vulnerability through targeted Hikvision camera exploits and network device compromise, risking HIPAA violations and patient data exposure via traffic interception.
Sources
- New Evooo1Bot Linux botnet turns routers into traffic relay nodeshttps://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/Verified
- CVE-2025-29635: Mirai Campaign Targets D-Link Deviceshttps://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devicesVerified
- Exploitation of Wazuh CVE-2025-24016 vulnerability leads to Mirai botnet distributionhttps://www.broadcom.com/support/security-center/protection-bulletin/exploitaiton-of-wazuh-cve-2025-24016-vulnerability-leads-to-mirai-botnet-distributionVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the botnet's ability to exploit vulnerabilities, escalate privileges, move laterally, establish command and control, and exfiltrate data, thereby reducing the attack's overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The botnet's ability to exploit known vulnerabilities in internet-facing devices would likely be constrained, reducing the likelihood of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The malware's ability to escalate privileges and establish persistence would likely be constrained, reducing the scope of its impact.
Control: East-West Traffic Security
Mitigation: The botnet's ability to move laterally within the network would likely be constrained, reducing its reachability to other devices.
Control: Multicloud Visibility & Control
Mitigation: The botnet's ability to establish encrypted command and control communications would likely be constrained, reducing its ability to evade detection.
Control: Egress Security & Policy Enforcement
Mitigation: The botnet's ability to exfiltrate sensitive information would likely be constrained, reducing the risk of data loss.
The botnet's ability to utilize compromised devices for proxying malicious traffic and launching DDoS attacks would likely be constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- Network Infrastructure
- Remote Access Services
- Data Transmission
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of network traffic data and credentials due to compromised routers acting as proxy nodes.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized access attempts.
- • Utilize Egress Security & Policy Enforcement to prevent unauthorized outbound communications and data exfiltration.
- • Apply Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads at the network perimeter.
- • Ensure regular firmware updates and replacement of default credentials on all internet-facing devices to mitigate exploitation of known vulnerabilities.



