Skip to main content

Morning Overview

Old Wi-Fi routers are being hijacked by hackers, and a few models keep showing up

A wireless router bought a decade ago can still hand out Wi-Fi just fine, even though the company that built it stopped writing security patches for it years earlier. That gap between still working and still being safe has become one of the most exploited weaknesses in home networking, and federal investigators say organized cybercriminals are actively hunting for it. The routers being swept up are not exotic equipment; they are ordinary consumer models that many households never got around to replacing, often because nothing about the device’s day-to-day performance ever signaled a problem.

Why Firmware Support Ends Long Before the Hardware Fails

Every router relies on firmware, the built-in software that manages its Wi-Fi radios, its administrative login screen and the way it forwards traffic between a home network and the wider internet. When a manufacturer declares a model end of life, it stops issuing firmware updates, so any security flaw discovered afterward is never patched on that device. Most consumer router lines get roughly three to five years of active security support before a manufacturer moves on to newer hardware, a window that can pass unnoticed by an owner who bought the device once and never thought about it again. The physical hardware can keep functioning for years past that point, which is exactly why an owner has no obvious signal that the box quietly routing their internet traffic has become a liability rather than an asset.

A Malware Family Built to Scan for Old Firmware

Investigators have tied much of the recent activity to a malware family known as TheMoon, which does not need a stolen password to break in. According to an FBI advisory, the malware scans the internet for routers with remote administration switched on, finds ones running outdated firmware, and plants itself once it locates a way inside. Once installed, it does not simply sit idle: it contacts a command-and-control server for instructions, which can include scanning for other vulnerable routers to recruit or making the hijacked device available for rent as a disguised relay point for someone else’s internet traffic. That rental model is what turns an individual infection into an ongoing business, since a single operator can control thousands of compromised routers scattered across different cities, states and countries at once.

A Recurring Cast of Discontinued Router Models

What makes the threat easier to track is that the same handful of devices keep turning up compromised. The FBI’s advisory identified roughly a dozen discontinued Linksys models still connected to home networks years after the company stopped supporting them, including devices sold under names like the E1200, E2500, E1000, E4200 and WRT320N. None of those routers still receive security updates, and several were shipped with remote-management features switched on by default, a setting that makes them far easier to locate and break into from anywhere in the world. A model number is usually printed on a sticker on the underside or back panel of the device, which is the fastest way for an owner to check whether their own hardware matches a list like this one without digging through settings menus.

Turning Thousands of Home Routers Into Criminal Infrastructure

A single hijacked router is not especially valuable on its own, but thousands of them stitched together become something else: a distributed network capable of launching attacks, relaying stolen data or routing someone else’s activity through an ordinary residential address. That last use is particularly attractive to criminals, since traffic that appears to originate from a home internet connection in a specific city draws far less scrutiny than traffic coming from a known data-center server. Residential proxy networks built this way get used for credential-stuffing attempts against retail and banking sites, for automated ad fraud, and for slipping past geographic or fraud-detection filters that would otherwise flag traffic coming from a known data center. Buyers can rent access to these networks by the hour, spreading activity across thousands of compromised routers so that no single address is used long enough to get flagged.

Reducing the Risk From an Aging Router

There is rarely a dramatic sign that a router has been compromised, since the malware is designed to run quietly without slowing down ordinary browsing enough to notice. The most reliable response is also the simplest: a router that no longer receives security updates from its manufacturer should be retired rather than kept in service indefinitely. Until a replacement is in place, switching off remote administration closes the door the malware relies on to reach the device from outside the network, and disabling any feature that automatically opens ports to the internet removes another common entry point. Restarting a router can briefly clear an infection that lives only in memory, but it does nothing to fix the underlying flaw, so the same device can be reinfected within hours if it remains reachable from the open internet. Routers supplied and actively maintained by an internet provider, or newer models that install security updates automatically, sidestep the problem entirely by not depending on an owner to track end-of-life dates themselves.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview