Skip to main content

Morning Overview

Your router may be the weakest link in the house, and old ones stop getting fixes

Most households replace a laptop or a phone every few years without much thought, but the router sitting in a closet or on top of a bookshelf often stays plugged in for a decade or longer. That gap matters because a router is the single device standing between every phone, laptop, camera and smart speaker in the house and the open internet, and once its manufacturer stops issuing security patches, every device behind it inherits the risk of whatever new vulnerability turns up next.

What End Of Life Actually Means For A Router

When a manufacturer declares a router end of life, it has stopped selling the model and, more importantly, stopped releasing the firmware updates that patch newly discovered flaws, according to a Federal Bureau of Investigation advisory on the subject. Routers manufactured around 2010 or earlier are especially likely to have already crossed that line, the FBI notes, since most consumer networking gear is supported for only a limited run of years after release. Manufacturers rarely announce end-of-life dates loudly, which means the burden of checking typically falls on the owner rather than arriving as a notification the way a phone operating system might flag its own retirement. Unlike a phone that nags its owner with an update notification, a router can keep working normally for years after support ends, which is exactly why the loss of patching tends to go unnoticed until something exploits it.

What A Home Router Actually Does

A residential gateway, the technical term for the combined modem-router-firewall box that most internet providers supply, sits at the single choke point through which every packet entering or leaving a home network must pass. That central position is precisely what makes an aging, unpatched unit so valuable to criminals: compromising one router can expose or reroute traffic from every laptop, tablet, doorbell camera and game console connected to it, rather than requiring a separate attack on each device individually. Many households never touch the router again after an installer or a family member sets it up once, leaving default settings and factory passwords in place indefinitely. Internet service providers sometimes replace this equipment automatically when a plan changes, but self-purchased routers, the kind sold at retail electronics stores, are left entirely to their owners to track and eventually retire.

How TheMoon Malware Turns A Router Into Someone Else’s Tool

The FBI’s advisory ties the end-of-life router problem to a specific piece of malware called TheMoon, first identified on compromised routers in 2014 and still circulating in updated variants. TheMoon does not need a stolen password to get in; it scans the internet for routers with open ports and remote management left switched on, then sends a command to a vulnerable script to gain a foothold, the bureau explains. Once installed, the malware can turn the router into a proxy that criminals rent out through underground services, routing someone else’s illegal traffic, from cryptocurrency theft to other cybercrime, through the victim’s home internet connection without permission. A proxy server, in plain terms, is simply a relay that stands between a user and the wider internet, and criminals prize proxy relays built from ordinary home routers because traffic passing through them appears to originate from an unsuspecting household rather than from the criminal’s own infrastructure. The infected router can also be instructed to scan for other vulnerable devices nearby, letting the network of compromised hardware grow largely on its own.

The Warning Signs Most Owners Never Check

Because a hijacked router keeps handling ordinary browsing and streaming in the background, the FBI notes that infections are often noticed only through indirect symptoms: a device that runs unusually hot, connectivity that drops or slows without explanation, or settings in the admin panel that an owner does not remember changing. None of those signs point definitively at malware on their own, which is part of why the bureau recommends checking router settings periodically rather than waiting for a problem to announce itself. A router that has quietly become part of a criminal proxy network shows no outward indication in a browser or on a phone; the internet still works, just with an uninvited passenger riding along.

Concrete Steps The FBI Recommends Taking

The bureau’s guidance is specific rather than general. None of the fixes require specialized skill: the settings menu on nearly every consumer router includes a remote-management toggle and a password field, and a firmware-update check typically sits on the same administrative page. If a router is confirmed end of life, the top recommendation is replacing it outright with a currently supported model, since no firmware update will ever arrive to close newly found holes on discontinued hardware. Short of replacement, the FBI recommends installing every available security patch immediately, logging into the router’s settings to disable remote management, and using a unique password between sixteen and sixty-four characters rather than the default credentials printed on the device. Password hints, another convenience many owners leave enabled, give an attacker an additional shortcut and are among the settings the FBI specifically advises turning off. Owners who suspect their router is already compromised are directed to update firmware, change the password, reboot the device, and file a report with the FBI’s Internet Crime Complaint Center, which tracks these incidents nationally and has used similar reports to identify and disrupt earlier versions of the same proxy networks. The advisory frames the risk as sitting with widely sold consumer hardware in general rather than any single obscure or unusual product, since any router that has stopped receiving updates is a candidate regardless of brand.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview