Morning Overview

The FBI warns your old home router could be quietly hijacked to hide someone else’s crimes

Millions of home routers that no longer receive security patches are being silently converted into proxy servers, letting criminals route fraud, credential theft, and espionage through ordinary residential internet connections. The FBI has issued multiple alerts warning that cybercriminal proxy services are actively targeting these end-of-life devices, and the Department of Justice has dismantled several botnets that collectively infected machines across roughly 200 countries and generated tens of millions of dollars in illicit revenue. The owners of these routers, in most cases, have no idea their hardware is involved.

How end-of-life routers become criminal infrastructure

The core problem is straightforward: once a router manufacturer stops issuing firmware updates, known vulnerabilities go unpatched. Attackers scan for these devices, install malware, and reconfigure them to relay internet traffic on behalf of paying customers who want to hide their real location. The FBI warned that proxy services are exploiting end-of-life home and small-office routers using malware called TheMoon, which installs itself on unpatched devices and enrolls them into commercial proxy networks. Because the traffic exits through a residential IP address, it looks like normal household browsing to banks, retailers, and law enforcement databases.

Routers are not the only entry point. A separate FBI alert described how devices can also be enrolled into residential proxy networks through free VPN applications with buried terms of service, compromised Internet of Things devices, malware bundled with other software downloads, and so-called passive income apps that pay users small amounts to share their bandwidth. In many of these cases, the device owner either never consented or clicked through disclosure language designed to obscure what was actually happening.

The practical consequence for a household is severe. If a criminal buys proxy access and uses that connection to commit wire fraud or submit false benefit claims, the IP address logged by investigators belongs to the router owner, not the actual perpetrator. That can mean a knock on the door from federal agents, a frozen bank account, or an internet service provider termination, all before the homeowner understands what happened.

Botnets dismantled, but the scale keeps growing

Federal prosecutors have taken down several of these networks, and the case files reveal just how large the market for hijacked residential IPs has become. The 911 S5 botnet infected millions of computers across approximately 200 countries before a coordinated international operation dismantled it and led to the arrest of its administrator. Paying customers used the hijacked IP addresses to conceal their identities while committing fraud.

A separate operation targeted the websites Anyproxy.net and 5socks.net, which according to the U.S. Attorney’s Office for the Northern District of Oklahoma advertised over 7,000 proxies with subscription pricing ranging from $9.95 to $110 per month. Alleged proceeds from those proxy sales exceeded $46 million. The underlying malware infected older-model routers and reconfigured them as proxy servers without the owners’ knowledge, according to the DOJ case filing.

State-sponsored actors have exploited the same weakness. The Justice Department conducted a court-authorized disruption of a botnet controlled by Russia’s GRU Unit 26165, also known as APT28, which used hundreds of compromised Ubiquiti EdgeOS routers to conceal spearphishing and credential-harvesting operations. Separately, the U.S. government disrupted the KV Botnet, composed largely of Cisco and NetGear end-of-life routers, which China-linked group Volt Typhoon used to conceal hacking of critical infrastructure. A court affidavit in that case explained that the botnet transmitted encrypted traffic between infected routers so that hackers appeared to operate from U.S.-based small-office IP addresses rather than from China.

Why older home routers are attractive targets

Criminals favor aging home and small-office routers for several reasons. First, these devices often remain in service for years after vendors stop shipping firmware updates, leaving a long window during which known exploits work reliably. Second, consumers rarely log into their router’s administrative interface, which means attackers can change settings, install malicious scripts, and add new user accounts without attracting attention.

Third, residential connections offer something corporate networks do not: plausible deniability. Fraud detection systems and intrusion-detection tools are tuned to treat home IP addresses as low risk because they are associated with ordinary families rather than data centers or anonymization services. When illicit traffic appears to originate from a quiet suburban block, it is less likely to be automatically flagged or blocked.

Finally, many internet service providers ship low-cost routers with default passwords and remote management features enabled. Even when customers change the Wi-Fi network name and passphrase, the router’s administrative password may remain set to a manufacturer default that attackers can guess in seconds. Once compromised, these devices can be chained together into large proxy networks that are difficult for investigators to map and dismantle.

How proxy abuse affects victims and investigations

For individual households, the most immediate risk is being mistakenly associated with crimes they did not commit. Investigators initially see only the IP address that submitted a fraudulent loan application, accessed a stolen bank account, or probed a government system. Tracing that address leads to the subscriber of record, who may have no idea their router is part of a botnet.

Even when law enforcement quickly determines that the homeowner is a victim, the process can be disruptive. Agents may seize devices for forensic analysis, financial institutions can delay or block transactions pending review, and service providers might temporarily suspend accounts to contain suspected abuse. In neighborhoods where multiple homes use similar hardware from the same provider, a single vulnerable model can serve as an entry point to compromise many customers.

Proxy abuse also complicates broader cybercrime investigations. When attackers route operations through dozens or hundreds of residential nodes, each hop adds legal and technical hurdles. Investigators must obtain separate legal process for each jurisdiction, and the resulting delays give criminals time to pivot to new infrastructure or destroy evidence. In cases involving state-sponsored actors, the use of home routers can blur the line between traditional cybercrime and national security threats, forcing agencies to coordinate across different legal authorities and response frameworks.

What consumers can do to reduce their risk

Experts say consumers cannot fully solve the problem on their own, but they can significantly reduce the chance their devices will be hijacked. The first step is to determine whether a router is still supported by its manufacturer. If firmware updates have stopped, replacing the hardware is the safest option, even if the device appears to work normally. When new equipment is installed, users should change default administrative passwords, disable remote management features they do not need, and enable automatic updates whenever possible.

Households should also be cautious about software and services that promise free VPN access or passive income in exchange for sharing bandwidth. Carefully reading terms of service, checking whether an app has a clear, reputable operator, and avoiding software from unknown publishers can help prevent devices from being quietly enrolled into proxy schemes. If a service’s business model is unclear or relies on vague language about “network optimization” or “traffic routing,” that can be a warning sign.

Monitoring home network activity can provide additional protection. Many modern routers offer basic logs that show connected devices and recent configuration changes. Unrecognized gadgets, frequent restarts, or settings that change without explanation may indicate compromise. In those cases, performing a factory reset, installing the latest firmware, and contacting the internet service provider for guidance can help restore control.

The policy and industry response

While individual actions matter, the scale of abuse highlighted in recent Justice Department and FBI cases suggests that a broader response is necessary. Security advocates have called for longer support windows for consumer networking gear, clearer labeling about end-of-life dates, and default configurations that prioritize safety over convenience. Some have urged regulators to treat basic router security as a product safety issue, arguing that insecure defaults expose not just the buyer but the wider internet to harm.

Industry groups and service providers are experimenting with ways to detect and quarantine compromised devices without cutting off customers entirely. Approaches under discussion include network-level scanning for known malicious traffic patterns, automated notifications when a router appears to be part of a botnet, and voluntary replacement programs for models linked to repeated abuse. These measures raise their own privacy and cost questions, but supporters argue they are necessary to keep criminal proxy networks from quietly expanding.

For now, the combination of aging hardware, opaque software ecosystems, and a thriving underground market for residential IP addresses ensures that home routers will remain attractive targets. Until manufacturers, regulators, and service providers align incentives around long-term security, millions of households will continue to serve as unwitting infrastructure for some of the internet’s most damaging crimes.

More from Morning Overview

*This article was researched with the help of AI, with human editors creating the final content.