2026-08-16
HN Discussion: 1 points, 0 comments
Router-based botnets aren't new, but each fresh strain reveals something about the state of edge-device security — and this one, dubbed Evooo1Bot, appears squarely aimed at converting compromised Linux routers into traffic relay nodes. That's a meaningful distinction from classic DDoS botnets. Relay-node infections are the raw material of residential proxy networks, credential-stuffing infrastructure, ad fraud pipelines, and increasingly, laundering layers for AI scraping traffic that gets blocked when it comes from cloud IP ranges.
What a technical reader will likely find in the BleepingComputer writeup:
The underrated angle here is the economic shift. Detection and takedown work on volumetric DDoS botnets has improved significantly. But relay botnets are quieter by design — a few kilobits per second per node, indistinguishable from a Netflix stream in aggregate — and the residential-proxy market has an insatiable, legally-gray demand. That makes them harder to justify prioritizing for ISPs and much more profitable for operators.
For anyone running a home lab, a self-hosted network monitoring stack, or edge infrastructure: this is exactly the kind of infection your ntopng flow data can catch — persistent outbound connections to unusual ASNs, unexpected SOCKS-shaped traffic patterns, or a router with steady low-bandwidth egress at 3 a.m. Worth watching for.
