A new botnet is renting out home routers as proxies - including yours, possibly
Your router gets no attention at all. It blinks away in a corner for five or six years and nobody logs into it after the day it was set up. That is precisely the appeal for whoever is running Evooo1Bot.
Fortinet's researchers published their analysis on August 13: a Linux botnet built on the leaked Mirai code, active since at least July. It gets in through 18 known, long-since-patched flaws - the oldest from 2007, the newest a 2025 bug in D-Link's DIR-868L - hitting kit from NETGEAR, TP-Link, D-Link, Tenda, Zyxel, Telesquare and Alcatel, plus D-Link network drives and Hikvision cameras. It also brute-forces SSH logins from a built-in list of more than 150 default username and password pairs, which is a polite way of saying it walks in wherever nobody changed the sticker password.
What happens next is the novel bit. Instead of just conscripting your router into a DDoS cannon - it inherits sixteen flooding methods for that as well - Evooo1Bot converts the device into a SOCKS5 proxy, either listening on port 1080 or dialling out to the operator's relay server so nothing suspicious is left exposed. Strangers' traffic then leaves the internet through your home IP address. It also sniffs authentication headers and cookies passing through, and phones its controller over port 443 so the chatter blends into normal HTTPS.
The real worry isn't a slower connection. It's that somebody else's activity now traces back to your address. Three things help: install the newest firmware from your router maker's own site, change the admin password if it's still the factory one, and turn off remote management so the admin page isn't reachable from the internet at all. A router that stopped getting firmware years ago should simply be replaced.
Tendvane's Network scan lists every device on your home network, which is the quickest way to notice the router, camera or old network drive you'd forgotten was still plugged in and facing outward.