Evooo1Bot Linux Malware Turns Vulnerable Edge Devices into SOCKS5 Proxy Relays

Evooo1Bot Linux Malware Turns Vulnerable Edge Devices into SOCKS5 Proxy Relays

A Linux botnet called Evooo1Bot is hijacking routers, firewalls and other edge devices with known security flaws, converting them into anonymous SOCKS5 proxies.

A newly observed Linux based botnet called Evooo1Bot is exploiting known security vulnerabilities in edge devices to turn them into SOCKS5 proxy servers, according to security researchers. This type of attack matters to website owners, businesses and home users alike because the devices being hijacked are often the same routers, firewalls and VPN gateways that sit at the boundary of a network and protect everything behind them.

To understand the risk, it helps to define a few terms. Linux is a widely used open source operating system that powers many embedded and network devices. A vulnerability is a weakness in software or hardware that can be exploited by an attacker. A botnet is a collection of internet connected devices that have been infected with malicious software and can be controlled remotely by an attacker. An edge device is any piece of hardware that sits at the edge of a network, such as a router, firewall, network attached storage appliance or Internet of Things sensor. A SOCKS5 proxy is a type of network relay that forwards internet traffic from one machine to another while hiding the original source address. When a device becomes a SOCKS5 proxy, it can be used to route malicious traffic through that device, making it appear as though the device owner is responsible for the activity.

Evooo1Bot takes advantage of known flaws in edge devices. The fact that these are known flaws is important because it means the security holes have already been identified and, in many cases, patches or updates are available. Attackers often scan the internet for devices that have not installed those patches or that still use default login credentials. Once a vulnerable device is found, the malware infects it and silently adds it to the botnet. From that point on, the attacker can instruct the compromised device to act as a SOCKS5 proxy, forwarding traffic for whoever pays for or controls the botnet.

The consequences for the device owner can be serious. A compromised router or firewall may become slow or unstable because its resources are being used to relay traffic for strangers. More importantly, the device's public IP address may be flagged by websites, email providers and security services as a source of abuse. That can lead to blocked website logins, rejected email, or even your own website being temporarily unreachable if the IP address is shared. Because SOCKS5 proxies hide the true origin of traffic, criminals commonly use them for credential stuffing attacks, spam campaigns, and other abusive activity. If your edge device is part of a botnet, your network and your reputation may be caught up in that activity without your knowledge.

Protecting yourself starts with basic device hygiene. First, update the firmware (the built-in software that controls the device) on every router, firewall and other edge device. Manufacturers release firmware updates to close known security holes, but many users never install them. Second, change any default administrator password to a long, unique passphrase, because default credentials are one of the easiest ways for attackers to get in. Third, turn off remote management or wide area network (WAN) access on the router unless you absolutely need it, and if you do need it, restrict it to specific IP addresses. Fourth, place smart home and Internet of Things devices on a separate guest network so a compromised camera or thermostat cannot reach your main computers or the router's management page. Fifth, periodically log into the router and review the list of connected devices; if you see something unfamiliar, investigate it. For organizations that need help inventorying their edge devices and applying patch discipline, AEU-I, our security focused IT and consulting practice, can assess infrastructure and implement hardening measures to reduce the chance your network is taken over by a botnet.

The Evooo1Bot activity is a reminder that even small, unglamorous devices can become powerful tools for attackers when left unpatched. Website owners and businesses should treat every internet facing device as a potential entry point and keep it updated, locked down and monitored. The good news is that the flaws being exploited are known, so the fix is usually straightforward: update, change defaults and limit exposure. Taking these steps now can keep your network from becoming someone else's anonymous proxy.

How to Protect Yourself

  1. Update the built-in software (firmware) on your router and other network devices by logging into their settings and checking for updates, and turn on automatic updates if available.
  2. Change the default administrator password on every router, firewall or smart device to a long and unique passphrase.
  3. Turn off remote management or WAN access on your router so it cannot be reached from the internet.
  4. Put smart home and Internet of Things devices on a separate guest network so they cannot reach your main computers.
  5. Log into your router and look at the list of connected devices, and investigate any device you do not recognize.
  6. Restart your router periodically and avoid leaving it online for months without a reboot.

Related AEU services

  • AEU-I IT and security consulting