New Evooo1Bot Linux botnet turns routers into traffic relay nodes

2026-08-16

Link: https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/

HN Discussion: 1 points, 0 comments

Router-based botnets aren't new, but each fresh strain reveals something about the state of edge-device security — and this one, dubbed Evooo1Bot, appears squarely aimed at converting compromised Linux routers into traffic relay nodes. That's a meaningful distinction from classic DDoS botnets. Relay-node infections are the raw material of residential proxy networks, credential-stuffing infrastructure, ad fraud pipelines, and increasingly, laundering layers for AI scraping traffic that gets blocked when it comes from cloud IP ranges.

What a technical reader will likely find in the BleepingComputer writeup:

The underrated angle here is the economic shift. Detection and takedown work on volumetric DDoS botnets has improved significantly. But relay botnets are quieter by design — a few kilobits per second per node, indistinguishable from a Netflix stream in aggregate — and the residential-proxy market has an insatiable, legally-gray demand. That makes them harder to justify prioritizing for ISPs and much more profitable for operators.

For anyone running a home lab, a self-hosted network monitoring stack, or edge infrastructure: this is exactly the kind of infection your ntopng flow data can catch — persistent outbound connections to unusual ASNs, unexpected SOCKS-shaped traffic patterns, or a router with steady low-bandwidth egress at 3 a.m. Worth watching for.

Why it deserves more upvotes: Relay botnets are the invisible backbone of the residential proxy economy, and this one targets the exact class of Linux edge devices most home and small-business networks run unpatched.

All newsletters