Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Columbia U Will Pay $750M to Survivors of OB-GYN Robert Hadden — ProPublica

    U.S.-Canada War Planning Is Surprisingly Common

    End-of-life router botnet shut, 4 ‘foreign hackers’ charged • The Register

    Facebook X (Twitter) Instagram
    Trending
    • Columbia U Will Pay $750M to Survivors of OB-GYN Robert Hadden — ProPublica
    • U.S.-Canada War Planning Is Surprisingly Common
    • End-of-life router botnet shut, 4 ‘foreign hackers’ charged • The Register
    • Don’t Succumb to Climate Fatalism
    • Pentagon orders military to pull books related to DEI and ‘gender ideology’ | US military
    • Pope Leo identifies AI as main challenge in first meeting with cardinals | Religion News
    • Labour to unveil big immigration plans next week
    • Kwik Fit founder Sir Tom Farmer dies aged 84
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»End-of-life routers hacked for cybercrime proxy networks
    Cyber

    End-of-life routers hacked for cybercrime proxy networks

    mediamillion1000@gmail.comBy [email protected]May 9, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    End-of-life routers hacked for cybercrime proxy networks
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    End-of-life routers hacked for cybercrime proxy networks

    The FBI warns that threat actors are deploying malware on end-of-life (EoL) routers to convert them into proxies sold on the 5Socks and Anyproxy networks.

    These devices, which were released many years back and no longer receive security updates from their vendors, are vulnerable to external attacks leveraging publicly available exploits to inject persistent malware. 

    Once compromised, they are added to residential proxy botnets that route malicious traffic. In many cases, these proxies are used by cybercriminals to conduct malicious activities or cyberattacks.

    “With the 5Socks and Anyproxy network, criminals are selling access to compromised routers as proxies for customers to purchase and use,” explains the FBI Flash advisory.

    “The proxies can be used by threat actors to obfuscate their identity or location.”

    The advisory lists the following EoL Linksys and Cisco models as common targets:

    • Linksys E1200, E2500, E1000, E4200, E1500, E300, E3200, E1550
    • Linksys WRT320N, WRT310N, WRT610N
    • Cradlepoint E100
    • Cisco M10

    The FBI warns that Chinese state-sponsored actors have exploited known (n-day) vulnerabilities in these routers to conduct covert espionage campaigns, including operations targeting critical U.S. infrastructure.

    In a related bulletin, the agency confirms that many of these routers are infected with a variant of the “TheMoon” malware, which enables threat actors to configure them as proxies.

    “End of life routers were breached by cyber actors using variants of TheMoon malware botnet,” reads the FBI bulletin.

    “Recently, some routers at end of life, with remote administration turned on, were identified as compromised by a new variant of TheMoon malware. This malware allows cyber actors to install proxies on unsuspecting victim routers and conduct cyber crimes anonymously.”

    Once compromised, the routers connect to command and control (C2) servers to receive commands to execute, such as scanning for and compromising vulnerable devices on the Internet.

    The FBI says that the proxies are then used to evade detection during cryptocurrency theft, cybercrime-for-hire activities, and other illegal operations.

    Common signs of compromise by a botnet include network connectivity disruptions, overheating, performance degradation, configuration changes, the appearance of rogue admin users, and unusual network traffic.

    The best way to mitigate the risk of botnet infections is to replace end-of-life routers with newer, actively supported models.

    If that is impossible, apply the latest firmware update for your model, sourced from the vendor’s official download portal, change the default admin account credentials, and turn off remote administration panels.

    The FBI has shared indicators of compromise associated with the malware installed on EoL devices.

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    cybercrime Endoflife hacked networks proxy routers
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleEU: Access to a lawyer in juvenile justice proceedings remains a key concern in several EU Member States
    Next Article Pope Leo XIV holds first mass as pontiff in Sistine Chapel – live | Pope Leo XIV
    [email protected]
    • Website

    Related Posts

    End-of-life router botnet shut, 4 ‘foreign hackers’ charged • The Register

    May 10, 2025

    ICE’s Deportation Airline Hack Reveals Man ‘Disappeared’ to El Salvador

    May 10, 2025

    What is CTEM? Continuous visibility for identifying real-time threats

    May 10, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Columbia U Will Pay $750M to Survivors of OB-GYN Robert Hadden — ProPublica

    U.S.-Canada War Planning Is Surprisingly Common

    End-of-life router botnet shut, 4 ‘foreign hackers’ charged • The Register

    Don’t Succumb to Climate Fatalism

    Trending Posts

    Columbia U Will Pay $750M to Survivors of OB-GYN Robert Hadden — ProPublica

    May 10, 2025

    U.S.-Canada War Planning Is Surprisingly Common

    May 10, 2025

    End-of-life router botnet shut, 4 ‘foreign hackers’ charged • The Register

    May 10, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Columbia U Will Pay $750M to Survivors of OB-GYN Robert Hadden — ProPublica
    • U.S.-Canada War Planning Is Surprisingly Common

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.