Fortinet has been tracking Evooo1Bot, a Mirai-based modular botnet hitting internet-facing gateway devices since at least July 2026.
The device list is the usual crowd: Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and D-Link routers and gateways, with further exploitation aimed at Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers and D-Link NAS devices.
What it does with them is the part worth reading.
Not a DDoS cannon
Mirai's descendants are usually described as DDoS botnets, and that framing is a decade old.
Evooo1Bot turns each compromised router into a SOCKS5 proxy node. The uses Fortinet lists:
- Concealing malicious traffic
- Circumventing geographic restrictions
- Reaching networks through compromised systems
- Monetisation through residential proxy services
That last item is the business model. A residential IP address — one belonging to a real home broadband line — is worth money, because it defeats the reputation checks that block datacentre IPs. Fraud, scraping, credential stuffing and ad fraud all pay for clean residential exit nodes.
So your router is not being conscripted into an attack. It is being rented out, and the traffic that leaves your line is somebody else's.
This is the supply side of a market we wrote about from the demand side: UNC6671 authenticating through residential broadband pools to look like a normal employee, and Sable Squirrel buying aged domains for the same reputation reason. Reputation is the scarce commodity, and it is being farmed.
The mechanics
Exploitation uses known vulnerabilities — no zero-days. Then:
a script downloads one of the 12 available malware builds that match the host's CPU architecture, then clears Bash history to wipe traces of the attack
Twelve architecture-specific builds is a maintenance commitment. Somebody is deliberately covering the long tail of consumer gateway hardware — MIPS, ARM variants, whatever the cheap boxes run.
Clearing shell history is the tell that this is aimed at devices where a human might one day log in and look.
Why nobody notices
A compromised router shows no symptom the owner would recognise. No slow machine, no popups, no ransom note. Slightly more upstream traffic, and an IP address that starts turning up on blocklists.
The one consequence most people eventually feel is the second-order one: sites start treating your connection as suspicious. Captchas everywhere, blocked sign-ups, failed card payments. Almost nobody traces that back to the router.
What to do
Fortinet's guidance, in the order that actually matters:
- Disable remote access panels. Web administration reachable from the internet is how nearly all of these start. This single change removes most of the exposure.
- Change default admin credentials. Still the most common way in.
- Update firmware — and check, because most consumer routers do not do it automatically and never tell you.
- Replace unsupported devices. A gateway that stopped getting firmware three years ago is not going to be patched, and it is on the target list precisely because of that.
If you manage an estate: cheap gateways in branch offices, retail sites and remote workers' homes are the ones on this list, and they are usually owned by nobody in particular.