Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Network Security - FBI Warns: End-of-Life Routers Exploited by Cyber Criminal Proxy Services
Network Security Hardware Security Latest News Malware News & Analysis Security

FBI Warns: End-of-Life Routers Exploited by Cyber Criminal Proxy Services

Kirsten DoyleBy Kirsten DoyleMay 9, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
End-of-Life Routers Exploited
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In a recent security advisory, the FBI warned of a quietly growing cyber threat: outdated home and small business routers are being turned into tools for criminal anonymity. 

Bad actors are compromising end-of-life (EoL) routers (devices no longer supported by their manufacturers) to install malware and conscript them into sprawling proxy networks like 5Socks and AnyProxy. Once infected, these routers become conduits for malicious traffic, obfuscating the true origin of cyberattacks and illicit activities. 

“The botnets are used in various ways, such as launching coordinated attacks or selling access to the devices. With the 5Socks and Anyproxy network, criminals are selling access to comporomised routers as proxies for customers to purchase and use. The proxies can be used by treat actors to obfuscate their identity or location,” the FBI said.  

Outdated Tech, Fresh Targets 

The hardware in question isn’t fresh off the shelf. Many of these routers, mostly models from Linksys, Cisco, and Cradlepoint, were released over a decade ago. They no longer receive firmware updates, meaning they’re defenseless against modern exploits. They include Linksys E1200, E2500, WRT310N, Cisco M10, Cradlepoint E100, and similar legacy gear. 

Attackers exploit well-documented vulnerabilities and inject persistent malware, often without needing a password. If remote administration features are left enabled, it is even easier. 

Meet TheMoon Malware 

At the heart of these attacks is a familiar name: TheMoon malware. First spotted in the wild back in 2014, it has evolved considerably. In another advisory, the FBI warned that the latest variant has been observed scanning the internet for vulnerable devices, exploiting open ports, and installing proxy services, all without user interaction. 

Once a device is compromised, it phones home to a command-and-control (C2) server, awaiting instructions. These may include scanning for other routers to infect, expanding the botnet, and helping criminals reroute web traffic to cover their tracks. 

Why Proxies Matter in Cybercrime 

A proxy server acts like a middleman between a user and the Internet. Malefactors exploit this to mask their real IP addresses, making their actions appear to come from legitimate residential networks. That means when attackers are logging into stolen crypto wallets, buying illegal services, or launching phishing attacks, an innocent bystander’s router could be doing the dirty work, without their knowledge. 

These aren’t just isolated, low-level nuisances. This kind of proxy network is sold on the dark web to other criminals, creating a cascade effect where one vulnerable device can facilitate dozens of crimes. 

Signs of Compromise 

There are several telltale signs that a router has been hijacked: 

  • Internet connectivity that is suddenly sluggish or unreliable 
  • Devices overheating or randomly rebooting 
  • Settings changed without manual intervention 
  • Remote management mysteriously turned on 

Protecting Users, Businesses 

The FBI offers practical steps to protect users and businesses: 

  • Replace outdated routers: If your device is no longer supported, it’s time for an upgrade. 
  • Disable remote admin: This is one of the most exploited features—turn it off immediately. 
  • Update firmware: If patches are still available, apply them now. 
  • Use strong, unique passwords: Long, random, and not reused across devices or accounts. 
  • Reboot and reset: If you suspect foul play, reset your router and change all associated credentials. 

Anyone who believes their router has been compromised or used as part of a proxy network is advised to: 

  • Report the incident to the FBI’s Internet Crime Complaint Center at www.ic3.gov 
  • Notify their ISP or account provider 
  • Change all related passwords and monitor for suspicious activity 
Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Major US telecom providers debut C2 ISAC to counter AI-driven threats

May 26, 20264 Mins Read

FCC Blocks Foreign-Made Routers, Citing National Security Risks

March 26, 20268 Mins Read

Cutting Into Overtime, Not Corners: How Network Automation Drives Business Value

March 13, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}