Federal prosecutors have charged four men from Russia and Kazakhstan with running a proxy botnet that quietly hijacked older Wi-Fi routers, turning them into anonymous internet relays sold to paying subscribers. The operation, tied to the websites Anyproxy.net and 5socks.net, infected end-of-life routers with a variant of TheMoon malware, a strain that has circulated since 2014. Owners of the compromised devices were never notified, and their home IP addresses were resold so that criminal traffic appeared to originate from ordinary households.
How memory-resident malware keeps dead routers useful to criminals
The technical detail at the center of this case is deceptively simple. According to an unsealed FBI affidavit filed in the Northern District of Oklahoma, the malware resides in short-term memory rather than writing itself to the router’s permanent storage. That design choice has a direct consequence for anyone who owns one of the affected devices: rebooting the router clears the infection temporarily, but it does not patch the vulnerability that allowed the breach in the first place.
The same affidavit describes Turkey-based command-and-control infrastructure that repeatedly scans for and re-exploits routers after a power cycle. Because the targeted models have reached end-of-life status and no longer receive firmware updates from their manufacturers, every reboot simply resets the clock. The malware returns, reconnects to its operators, and resumes proxying traffic. This loop gives the botnet a persistence advantage that disk-based malware on actively patched systems would not enjoy. A router that stays plugged in and unpatched can be re-enrolled in the proxy network within minutes of losing its previous infection.
The FBI says it partially reverse-engineered the installed malware during its investigation. TheMoon scans for open ports on neighboring devices and, in some cases, does not require a password to gain access, according to the bureau’s public alert. That scanning behavior lets the botnet grow without any action from its operators beyond maintaining the C2 servers. Each newly discovered vulnerable router can be added to the pool of available residential IP addresses without the knowledge or consent of its owner.
Because the malware never persists to disk, traditional antivirus tools running on laptops or phones behind the router will not see the infection. From a household’s perspective, the only visible symptom might be slightly degraded network performance or unfamiliar traffic patterns. To the outside world, however, the compromised router becomes an attractive launchpad for fraudsters seeking to blend in with normal residential users.
Four defendants, two proxy storefronts, and a federal indictment
The criminal case is captioned United States v. Chertkov et al., 4:25-cr-00160-JDR. The unsealed indictment names four defendants: Chertkov, Morozov, Rubtsov, and Shishkin. Prosecutors allege the group infected older-model wireless routers with malware without the owners’ knowledge, reconfigured them, and then sold access through two commercial proxy websites.
Subscribers who paid for the service could route their internet traffic through the compromised routers. From the perspective of any website or online service receiving that traffic, the connection appeared to come from the victim router’s residential IP address, not from the actual user. That capability is valuable to anyone trying to evade geographic restrictions, commit fraud under a clean-looking IP, or obscure the origin of cyberattacks. By offering thousands of such endpoints, the operators effectively monetized a hidden network of hijacked home and small-business devices.
The Justice Department announced that the botnet was dismantled in a coordinated action involving law enforcement agencies in multiple countries, and the indictment was unsealed as part of that effort. The takedown included seizing or redirecting command-and-control infrastructure so that infected routers could no longer be rented out as proxies. The charges against the four administrators signal a shift toward holding proxy-service operators accountable, not just the downstream criminals who purchase anonymity.
According to prosecutors, the defendants marketed their proxy access to a global customer base while concealing the true nature of the underlying infrastructure. Buyers saw a menu of residential IP addresses available by country and region, with pricing tiers based on volume and duration. The indictment alleges that the defendants knew their services were being used for fraud and other criminal activity, yet continued to expand the botnet and add more compromised routers to increase revenue.
What the FBI’s router list leaves unanswered
The FBI’s public alert references a specific set of end-of-life router models vulnerable to TheMoon, but the primary documents available do not enumerate every affected make and firmware version in full detail. That gap matters for consumers trying to determine whether their own hardware is at risk. Without a complete, model-by-model checklist published alongside the alert, router owners are left to cross-reference general descriptions of “older-model wireless routers” against their own equipment.
The available court filings and the FBI’s cybersecurity advisory also do not disclose the total number of infected devices or break down where victims are concentrated geographically. The affidavit confirms the investigative methods and the malware’s behavior but stops short of quantifying the botnet’s full scale. No statements from router manufacturers appear in the public record, leaving open the question of whether any vendor plans voluntary recall programs or extended security patches for the affected models.
The indictment targets administrators based in Russia and Kazakhstan, and the C2 servers are located in Turkey. Extradition prospects for the four defendants remain unclear given current diplomatic realities, and the court docket does not yet reflect any custody status updates. For now, the legal case proceeds largely on paper, while the technical cleanup of infected routers will depend on whether owners proactively replace unsupported hardware.
What router owners can realistically do next
For anyone running an older Wi-Fi router that no longer receives security updates, the practical first step is straightforward: check the manufacturer’s support page to confirm whether the device has reached end-of-life status. If it has, replacing it with a currently supported model is the only reliable fix. Rebooting alone will not close the hole, because the vulnerability that allowed TheMoon onto the device remains unpatched, and scanning infrastructure controlled by the botnet’s former operators-or by copycat groups-can simply reinfect it.
Until a replacement is installed, users can reduce risk by disabling remote administration features, changing default passwords, and ensuring that any available firmware updates are applied. These measures cannot compensate for a complete lack of vendor support, but they may narrow the attack surface for opportunistic scans. Network administrators overseeing many small sites, such as retail locations or branch offices, may need to conduct inventory checks to identify and phase out legacy routers that match the categories described in the FBI materials.
The broader lesson from the Anyproxy and 5socks case is that end-of-life hardware does not simply become obsolete; it can be actively dangerous. As manufacturers stop issuing patches, attackers gain a permanent foothold in the installed base of aging equipment. Memory-resident malware like TheMoon exploits that gap, turning forgotten routers into a commodity resource for criminal markets. The Justice Department’s latest charges underscore that even when a botnet is dismantled, the underlying vulnerabilities remain until owners retire the affected devices.
More from Morning Overview
*This article was researched with the help of AI, with human editors creating the final content.