FBI Sounds Alarm on Cyber Gangs Hijacking Obsolete Routers for Covert Online Operations
The FBI has released a high-priority security alert spotlighting a growing threat: cybercriminal groups are repurposing outdated internet routers—devices long abandoned by manufacturers—to create stealthy proxy networks used in illegal schemes.
In its latest FLASH report, the agency outlines how attackers are targeting end-of-support routers—no longer shielded by firmware updates or security patches—and turning them into anonymous gateways that disguise the origin of cyberattacks.
Targets: Outdated Routers from 2010 and Earlier
Investigators have singled out 13 aging router models, primarily older Linksys and Cisco-branded hardware, currently under active exploitation:
- Linksys: E1200, E2500, E3200, WRT320N, WRT310N
- Cisco Linksys: E1000, E1500, E1550, E4200, WRT610N
- Cradlepoint: E300, E100
- Cisco: M10
According to the FBI, routers released around 2010 or earlier are especially susceptible due to discontinued support, leaving them exposed to well-documented vulnerabilities.
A Familiar Malware Resurfaces
The resurgence of TheMoon malware—a botnet first uncovered in 2014—marks a dangerous turn. Unlike typical malware, TheMoon doesn’t need a password to breach these routers. It scans for open ports, delivers malicious code, and waits for instructions from remote hacker-controlled command centers.
A distinctive feature of the current infection wave is the deployment of a file called “.nttpd”, which creates a version-tracked process ID (PID). Once active, it modifies firewall rules to block access on common ports (8080 and 80), while selectively allowing traffic from attacker-approved IP ranges—essentially locking others out while preserving control for the attackers.
Cybercrime Infrastructure Hidden in Plain Sight
These compromised routers have been tied to underground proxy networks such as Anyproxy and 5Socks, both recently dismantled by law enforcement. These services monetized the hacked devices by leasing them as anonymized IP relays for criminal use.
“When these proxies are used to access websites or commit fraud, the real IP addresses of the perpetrators remain hidden,” the FBI noted. This level of digital camouflage is instrumental in enabling a range of crimes—from crypto heists to trafficking on illicit platforms.
Exploits in the Wild: How They Break In
Hackers are exploiting weaknesses in unpatched firmware or brute-forcing weak admin credentials. One notable example is the Seowon SLR-120 vulnerability (CVE-2020-17456), which enables remote code execution without authentication—simply by sending a specially crafted POST request to a router’s system log function.
After breaching the device, malicious code execution begins—often mirroring public proof-of-concept exploits already circulating on hacker forums.

Malicious Code Execution Locks In Long-Term Control
Once triggered, the attacker’s script retrieves a malicious package and activates it—silently embedding itself within the device to maintain ongoing, unauthorized access.
FBI’s Urgent Cybersecurity Advisory: How to Stay Protected
To counter this evolving threat, the FBI urges the public to take immediate preventative action:
- Retire outdated routers and upgrade to models that receive active support and security maintenance.
- Keep firmware up to date—check regularly for manufacturer-issued patches and install them without delay.
- Shut down remote access features, which can expose your router to internet-based intrusion attempts.
- Use long, complex passwords (ideally 16–64 characters) that are unique to your router and not reused elsewhere.
- Restart your router regularly to disrupt temporary malware that may be lurking in volatile memory.
Warning Signs: Could Your Router Be Compromised?
Watch for symptoms that may indicate foul play:
- Device runs unusually hot
- Network settings have mysteriously changed
- Frequent disconnections or sluggish internet performance
As malicious campaigns become more sophisticated and widespread, the FBI strongly advises a proactive approach. Replacing unsupported hardware and following best-practice security habits is the most reliable way to shield home and business networks from exploitation.




