Evooo1Bot exploits legacy router flaws to build pervasive proxy and surveillance network

A new botnet, Evooo1Bot, leverages decades-old router flaws to hijack devices, transforming them into proxy relays and tools for traffic sniffing, posing a growing threat to both households and enterprises.

FortiGuard Labs says a new botnet known as Evooo1Bot is exploiting old router and appliance flaws to break into internet-facing devices, then turning them into proxy relays and traffic-sniffing nodes. The campaign, analysed on 13 August 2026 by Cara Lin, has been active since July and appears to be scanning for exposed systems across consumer and enterprise equipment. According to the report, the malware name comes from a string embedded in the samples.

At the centre of the attack is a command-injection flaw first disclosed in 2007, now identified by the National Vulnerability Database as CVE-2007-5146. FortiGuard says the botnet also carries exploit code for nine more vulnerabilities spanning devices from NETGEAR, Tenda, D-Link, Telesquare, Alcatel and Mitsubishi Electric, with the target list extending from home routers to industrial and communications gear. That breadth matters: once an abandoned device is still reachable from the internet, age offers little protection.

After compromise, the malware can be instructed to provide SOCKS5 proxy access, effectively turning the router into a relay for someone else’s traffic. FortiGuard says it can also sniff passing connections, extracting login headers and session cookies into a hidden file on the device. In practice, that means a household router can quietly observe traffic from laptops, phones and other connected devices while otherwise appearing to function normally.

The infection process is not limited to a single exploit path. FortiGuard reports that the malware also tries more than 150 username-and-password combinations over SSH, using login strings that include both default device credentials and common server accounts such as jenkins, postgres, oracle, nagios and deploy. The code also includes a second exploit set for targets including Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link’s Archer AX21, D-Link NAS devices, Kubernetes ingress-nginx, WSO2 and the MOVEit file-transfer platform.

Some of those embedded exploits, however, do not appear to work as written. FortiGuard says several are non-exploitable in their shipped form, and that the MOVEit entry does not match the expected upload flow. Even so, the campaign is designed to blend in: its command-and-control traffic uses HTTPS on port 443, the same port often used by legitimate router firmware checks. The malicious address identified in the report, 91.92.40.118, sits in an ASN that was first linked to abuse reports in early July, which aligns with the start of the campaign.

The code base also shows how familiar this class of malware has become. FortiGuard says the attack routines are derived from leaked Mirai source code and include multiple flood methods, plus an HTTP flood option, with builds prepared for different processor families. Persistence is equally blunt: the malware installs itself in several locations and creates a scheduled task that attempts to fetch and execute it again every five minutes. For owners of unsupported routers, D-Link’s own retirement notice for the DIR-868L is a reminder that patching is not always an option; sometimes the only practical answer is replacement. FortiGuard’s report also reflects a wider pattern seen across router malware, where botnets continue to harvest long-fixed flaws because exposed devices remain online and unmaintained.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.