Router abused as proxy network

New Linux Botnet Evooo1Bot Turns Routers into Traffic Relay Nodes

Backdoor, Linux, Linux security, Linux backdoor, Velvet Ant, linux login hack, hackers manipulate Linux login systems with backdoors, decade-long Linux cyber espionage campaign exposed, Linux Login, Hacker
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Stanislaw Mikulski / Shutterstock.com

Fortinet has discovered the new Linux botnet Evooo1Bot, which turns gateway devices into SOCKS5 relay nodes and additionally steals data.

Since at least July, Evooo1Bot has been targeting devices from manufacturers Alcatel, Netgear, Tenda, Mitsubishi Electric, Telesquare, and D-Link across various regions worldwide using known vulnerabilities. Fortinet researchers stated:

Ad

“While the malware continues to use the DDoS engine from the publicly leaked Mirai source code, it expands the original framework with numerous capabilities, including encrypted C2 communication, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated arsenal of exploits against several known vulnerabilities.”

Fortinet

Ad

Newer software versions additionally contain a separate module for exploiting vulnerabilities in Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS systems, WSO2 products, Kubernetes Ingress-NGINX, and vulnerable PHP-CGI installations, with Fortinet noting that some of the built-in exploits are improperly implemented and therefore fail.

If exploitation succeeds, a script downloads one of twelve available malware versions matching the respective processor architecture and subsequently deletes the Bash history to cover up traces of the attack. Evooo1Bot communicates in encrypted form over port 443 and extensively checks for debuggers, security tools, sandboxes, virtual machines, containers, and honeypots before its actual execution. For persistent access, the malware utilizes Systemd, SysV Init, shell profiles, as well as rc.local; a cron job also attempts to reload the core malware every five minutes.

Proxy function as a potential business model

Via an interactive shell, operators gain direct access to compromised systems, supplemented by commands for uploading and downloading files. A dedicated credential sniffer module also monitors the file /proc/net/tcp and attempts to intercept HTTP Basic Authentication and cookie headers. The SOCKS5 module supports both direct listening and a reverse relay mode, allowing attackers to obfuscate malicious traffic, bypass geographic restrictions, or potentially pivot into external networks via compromised systems. According to Fortinet, individual proxy sessions run independently of one another, and several can be opened simultaneously, which—with a sufficiently sized botnet—would enable monetization via residential proxy services.

The SSH scanner module tests 150 username-password combinations tailored to enterprise environments and additionally verifies whether a successful login lands on a honeypot. The DDoS module inherited from Mirai supports a total of 16 different attack methods, including UDP, DNS, SYN, ACK, and GRE floods, fragmented TCP packets, and an HTTP flood with freely configurable requests.

Recommended protective measures for Linux

To protect against such botnets, Fortinet recommends keeping IoT device firmware up to date at all times, replacing factory-default administrator credentials, disabling remote management interfaces, and replacing devices as soon as the respective manufacturer no longer offers support for them.

(Editorial Team)

Ad

Weitere Artikel