Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    US to fast-track investments from Middle East before Trump trip: Report | Donald Trump News

    Jeanine Pirro latest Fox News star to join Trump administration : NPR

    We Are Still Fighting World War II

    Facebook X (Twitter) Instagram
    Trending
    • US to fast-track investments from Middle East before Trump trip: Report | Donald Trump News
    • Jeanine Pirro latest Fox News star to join Trump administration : NPR
    • We Are Still Fighting World War II
    • US: Don’t Forcibly Transfer Migrants to Libya
    • Man charged with murder of 87-year-old in north London
    • ‘I freaked out and spent $400 online’
    • Police dismantles botnet selling hacked routers as residential proxies
    • Rallies held around Australia against sexual violence, anger that crisis not properly addressed during election | Domestic violence
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Police dismantles botnet selling hacked routers as residential proxies
    Cyber

    Police dismantles botnet selling hacked routers as residential proxies

    mediamillion1000@gmail.comBy [email protected]May 10, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Police dismantles botnet selling hacked routers as residential proxies
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Police dismantles botnet selling hacked routers as residential proxies

    Law enforcement authorities have dismantled a botnet that infected thousands of routers over the last 20 years to build two networks of residential proxies known as Anyproxy and 5socks.

    The U.S. Justice Department also indicted three Russian nationals (Alexey Viktorovich Chertkov, Kirill Vladimirovich Morozov, and Aleksandr Aleksandrovich Shishkin) and a Kazakhstani (Dmitriy Rubtsov) for their involvement in operating, maintaining, and profiting from these two illegal services.

    During this joint action dubbed ‘Operation Moonlander,’ U.S. authorities worked with prosecutors and investigators from the Dutch National Police, the Netherlands Public Prosecution Service (Openbaar Ministerie), and the Royal Thai Police, as well as analysts with Lumen Technologies’ Black Lotus Labs.

    Court documents show that the now-dismantled botnet infected older wireless internet routers worldwide with malware since at least 2004, allowing unauthorized access to compromised devices to be sold as proxy servers on Anyproxy.net and 5socks.net. The two domains were managed by a Virginia-based company and hosted on servers globally.

    “The botnet controllers require cryptocurrency for payment. Users are allowed to connect directly with proxies using no authentication, which, as documented in previous cases, can lead to a broad spectrum of malicious actors gaining free access,” Black Lotus Labs said.

    “Given the source range, only around 10% are detected as malicious in popular tools such as VirusTotal, meaning they consistently avoid network monitoring tools with a high degree of success. Proxies such as this are designed to help conceal a range of illicit pursuits including ad fraud, DDoS attacks, brute forcing, or exploiting victim’s data.”

    Map of infected routers
    Map of compromised routers (Black Lotus Labs)

    Their users paid a monthly subscription ranging from $9.95 to $110 per month, depending on the requested services. “The website’s slogan, ‘Working since 2004!,’ indicates that the service has been available for more than 20 years,” the Justice Department said today.

    The four defendants advertised the two services (promoting over 7,000 proxies) as residential proxy services on various websites, including ones used by cybercriminals, and they allegedly collected over $46 million from selling subscriptions providing access to the infected routers part of the Anyproxy botnet.

    They operated the Anyproxy.net and 5socks.net websites using servers registered and hosted at JCS Fedora Communications, a Russian internet hosting provider. They also used servers in the Netherlands, Türkiye, and other locations to manage the Anyproxy botnet and the two websites.

    They were all charged with conspiracy and damage to protected computers, while Chertkov and Rubtsov were also accused of falsely registering a domain name.

    5Socks.net seizure banner
    5Socks.net seizure banner (BleepingComputer)

    Targeting end-of-life (EoL) routers

    On Wednesday, the FBI also issued a flash advisory and a public service announcement warning that this botnet was targeting patch end-of-life (EoL) routers with a variant of the TheMoon malware.

    The FBI warned that the attackers are installing proxies later used to evade detection during cybercrime-for-hire activities, cryptocurrency theft attacks, and other illegal operations.

    The list of devices commonly targeted by the botnet includes Linksys and Cisco router models, including:

    • Linksys E1200, E2500, E1000, E4200, E1500, E300, E3200, E1550
    • Linksys WRT320N, WRT310N, WRT610N
    • Cisco M10 and Cradlepoint E100

    “Recently, some routers at end of life, with remote administration turned on, were identified as compromised by a new variant of TheMoon malware. This malware allows cyber actors to install proxies on unsuspecting victim routers and conduct cyber crimes anonymously,” the FBI said.

    “Such residential proxy services are particularly useful to criminal hackers to provide anonymity when committing cybercrimes; residential-as opposed to commercial—IP addresses are generally assumed by internet security services as much more likely to be legitimate traffic,” today’s indictment added. “In this way, conspirators obtained a private financial gain from the sale of access to the compromised routers.”

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    botnet dismantles hacked police proxies residential routers selling
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleRallies held around Australia against sexual violence, anger that crisis not properly addressed during election | Domestic violence
    Next Article ‘I freaked out and spent $400 online’
    [email protected]
    • Website

    Related Posts

    Yolk’s on you – eggs break less when they land sideways • The Register

    May 10, 2025

    The Signal Clone Mike Waltz Was Caught Using Has Direct Access to User Chats

    May 10, 2025

    DDoS-Attacken auf deutsche Städte | CSO Online

    May 10, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    US to fast-track investments from Middle East before Trump trip: Report | Donald Trump News

    Jeanine Pirro latest Fox News star to join Trump administration : NPR

    We Are Still Fighting World War II

    US: Don’t Forcibly Transfer Migrants to Libya

    Trending Posts

    US to fast-track investments from Middle East before Trump trip: Report | Donald Trump News

    May 10, 2025

    Jeanine Pirro latest Fox News star to join Trump administration : NPR

    May 10, 2025

    We Are Still Fighting World War II

    May 10, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • US to fast-track investments from Middle East before Trump trip: Report | Donald Trump News
    • Jeanine Pirro latest Fox News star to join Trump administration : NPR

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.