Your TV, Then Your Browser, Now Your Router. Evooo1Bot Turns Edge Hardware Into SOCKS5 Relays — the Fourth Harvesting Layer in Five Months.
- Patrick Duggan
- 4 hours ago
- 4 min read
FortiGuard Labs published on a previously undocumented Linux botnet family called Evooo1Bot, active since July 2026. It is Mirai-derived, which is unremarkable, and it has a SOCKS relay module, which is the part that matters.
We have been tracking the residential-proxy supply chain for five months. This is the fourth acquisition layer, and putting the four side by side says more than any one of them does.
The four layers, with dates
Layer one — device SDKs. March 12, the FBI issues advisory PSA260312 on residential proxy abuse. July 2, GTIG, the FBI, the IRS and Lumen unplug NetNut/Popa: two million hijacked home devices, mostly smart TVs and streaming boxes, infected via malicious SDKs baked into ordinary apps.
Layer two — platform enforcement pushes back. July 22, LG bans residential-proxy SDKs from webOS and starts scanning every app in its store for known proxy-provider code signatures; Samsung follows. The trigger was research finding that more than 42% of games and apps in LG's own store routed third-party traffic through the customer's television.
Layer three — browser extensions. August 12, Socket publishes 737 Chrome VPN extensions funnelling traffic through one SOCKS5 backend on port 1082, 274 of them impersonating 66 real privacy brands.
Layer four — the edge hardware itself. August 15, FortiGuard publishes Evooo1Bot.
We were careful in the last post not to claim the browser wave was caused by the device-layer takedown, and we are being careful again. Four dated events are not a causal chain. What they are is a clear picture of where the pressure is and is not: the device layer is contested, the platform stores are scanning, and the router in the utility cupboard has nobody policing it at all.
What Evooo1Bot actually is
It targets internet-facing edge networking equipment — routers, firewalls and IoT devices from Alcatel, D-Link, Mitsubishi Electric, Netgear, Tenda and Telesquare. It reuses Mirai's leaked DDoS engine and then adds the things Mirai never had: encrypted C2, multi-layered string encryption, an SSH brute-force scanner, a credential sniffer, an exploit arsenal against known vulnerabilities, and the SOCKS relay module.
Telemetry puts activity across North America, South America, Europe, India, China and Japan.
The relay design is worth reading closely. It converts a compromised router or firewall into a persistent SOCKS5 proxy node using an outbound reverse-relay architecture that decouples session control from proxy data traffic. The control channel and the traffic it carries are separate flows. That defeats detection logic that expects a proxy node to look like one connection doing both jobs, and it means the device dials out — so inbound firewall posture is irrelevant, exactly as it was with the vCenter reverse_ssh campaign this week.
Why the router is a better harvest than the TV
Each layer has been an upgrade for the operator, and this is the biggest one.
A hijacked smart TV gives you an IP address and nothing else. A malicious browser extension gives you an IP address plus plaintext for that browser's traffic. A compromised router or firewall gives you an IP address, a persistent always-on node that nobody ever reboots deliberately, and — per FortiGuard — the ability to pivot directly into the internal corporate network behind it.
That last capability changes the category. The first three layers were about borrowing residential IP addresses to launder somebody else's traffic. A SOCKS5 relay on the edge firewall is also a foothold on the network boundary, with a credential sniffer and an SSH brute-forcer already resident.
And nobody patches these. A television gets firmware from a vendor with an app store and a reputation to protect — which is precisely why LG and Samsung could act in July. A five-year-old Tenda router in a branch office has no store, no scanning, no update pressure, and no owner who thinks of it as a computer.
The detection that works across all four layers
We keep arriving at the same place, so it is worth stating as a rule rather than a tip.
Blocking the addresses is nearly worthless. These are consumables — a VPS is five euros, an extension is a new developer account, a router is somebody else's property. The infrastructure rotates faster than any blocklist.
The shape is durable. Across every layer, the giveaway is the same: a device on your network establishing an outbound relay session it has no business establishing, and carrying traffic that did not originate with it. For the browser layer that was SOCKS5 to port 1082. Here it is your edge device holding a long-lived encrypted outbound control channel plus a separate data flow.
So: watch egress from your network appliances, not just from your endpoints. A router or firewall is a thing that should be receiving management connections, not initiating persistent outbound sessions to hosts nobody can name. That single question — what is my firewall talking to, and why — catches this, catches the vCenter campaign, and catches whatever the fifth layer turns out to be.
If you run branch offices, hospitality, retail or industrial sites, the affected vendor list above is the inventory question to ask this afternoon.
Credit
The research is FortiGuard Labs'. We hold no first-party indicators on Evooo1Bot and are not claiming any — what we are contributing is the sequence, which only reads clearly if you have been keeping the dates for five months.
Ninety-five percent, as always. If the fifth layer turns out to be something other than edge hardware, we will have been wrong about where the pressure pushed it, and we will say so.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=your-tv-then-your-browser-now-your-router-evooo1bot-turns-edge-hardware-into-socks5-relays-the




Comments