{"id":677,"date":"2025-05-09T01:15:39","date_gmt":"2025-05-08T22:15:39","guid":{"rendered":"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/"},"modified":"2025-05-09T01:15:39","modified_gmt":"2025-05-08T22:15:39","slug":"fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/","title":{"rendered":"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks"},"content":{"rendered":"<p>The FBI has issued a warning regarding the exploitation of end-of-life (EoL) routers by threat actors who deploy malware to transform these devices into proxies for sale on the 5Socks and Anyproxy networks.<\/p>\n<p>EoL routers, which have not received security updates from manufacturers for many years, are particularly vulnerable to external attacks that leverage publicly available exploits to inject persistent malware. Once compromised, these routers become part of residential proxy botnets, funneling malicious traffic. Cybercriminals frequently use these proxies for various illegal activities, including cyberattacks.<\/p>\n<p>The FBI\u2019s advisory states, \u201cWith the 5Socks and Anyproxy network, criminals are selling access to compromised routers as proxies for customers to purchase and use.\u201d These proxies are utilized by threat actors to conceal their identities and geographical locations.<\/p>\n<p>The following EoL models have been identified as common targets:<\/p>\n<p>&#8211; Linksys E1200, E2500, E1000, E4200, E1500, E300, E3200, E1550<br \/>\n&#8211; Linksys WRT320N, WRT310N, WRT610N<br \/>\n&#8211; Cradlepoint E100<br \/>\n&#8211; Cisco M10<\/p>\n<p>Moreover, the FBI warns that Chinese state-sponsored actors have leveraged known vulnerabilities in these routers to execute covert espionage campaigns, including operations that target critical U.S. infrastructure.<\/p>\n<p>A related bulletin confirms that numerous routers have been infected with a variant of &#8220;TheMoon&#8221; malware, which enables threat actors to configure the devices as proxies. The bulletin notes, \u201cEnd of life routers were breached by cyber actors using variants of TheMoon malware botnet.\u201d It states that some EoL routers with remote administration enabled have been compromised by a new variant of TheMoon malware, facilitating anonymous cybercrime activities.<\/p>\n<p>Compromised routers connect to command and control (C2) servers to receive commands, such as scanning for and further compromising vulnerable devices across the Internet. The FBI highlights that these proxies aid in evading detection during various illicit operations, including cryptocurrency theft and cybercrime-for-hire activities.<\/p>\n<p>Common indicators of compromise by a botnet include disruptions to network connectivity, overheating, performance degradation, unauthorized configuration changes, the emergence of rogue administrative users, and atypical network traffic patterns.<\/p>\n<p>To mitigate the risk associated with botnet infections, organizations are advised to replace EoL routers with new, actively supported models. If replacement is not feasible, it is critical to apply the latest firmware updates sourced directly from the vendor\u2019s official download portal, change default administrative credentials, and disable remote administration features.<\/p>\n<p>The FBI has also provided indicators of compromise associated with the malware affecting EoL devices, equipping organizations with the tools necessary to protect against these growing threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The FBI has issued a warning regarding the exploitation of end-of-life (EoL) routers by threat actors who deploy malware to&#8230;<\/p>\n","protected":false},"author":1,"featured_media":680,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[54,96,93],"class_list":["post-677","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-malware","tag-proxies","tag-routers"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks\" \/>\n<meta property=\"og:description\" content=\"The FBI has issued a warning regarding the exploitation of end-of-life (EoL) routers by threat actors who deploy malware to...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-08T22:15:39+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"\u062f\u0642\u064a\u0642\u062a\u0627\u0646\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/\",\"url\":\"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/\",\"name\":\"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks.webp\",\"datePublished\":\"2025-05-08T22:15:39+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks.webp\",\"width\":1792,\"height\":1024,\"caption\":\"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks[:] - Trustcrypt","og_description":"The FBI has issued a warning regarding the exploitation of end-of-life (EoL) routers by threat actors who deploy malware to...","og_url":"https:\/\/trustcrypt.com\/ar\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/","og_site_name":"Trustcrypt","article_published_time":"2025-05-08T22:15:39+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"\u062f\u0642\u064a\u0642\u062a\u0627\u0646"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/","url":"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/","name":"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks.webp","datePublished":"2025-05-08T22:15:39+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/fbi-reports-legacy-routers-compromised-for-cybercriminal-proxy-networks.webp","width":1792,"height":1024,"caption":"FBI Reports: Legacy Routers Compromised for Cybercriminal Proxy Networks"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=677"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/677\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/680"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}