The FBI warns that threat actors are deploying malware on end-of-life (EoL) routers to convert them into proxies sold on the 5Socks and Anyproxy networks. These devices, which were released many years back and no longer receive security updates from their vendors, are vulnerable to external attacks leveraging publicly available exploits to inject persistent malware. Once compromised, they are added to residential proxy botnets that route malicious traffic. In many cases, these proxies are used by cybercriminals to conduct malicious activities or cyberattacks. "With the 5Socks and Anyproxy network, criminals are selling access to compromised routers as proxies for customers to purchase and use," explains the FBI Flash advisory. "The proxies can be used by threat actors to obfuscate their identity or location." The advisory lists the following EoL Linksys and Cisco models as common targets: The FBI warns that Chinese state-sponsored actors have exploited known (n-day) vulnerabilities in these routers to conduct covert espionage campaigns, including operations targeting critical U.S. infrastructure. In a related bulletin, the agency confirms that many of these routers are infected with a variant of the "TheMoon" malware, which enables threat actors to configure them as proxies. "End of life routers were breached by cyber actors using variants of TheMoon malware botnet," reads the FBI bulletin. "Recently, some routers at end of life, with remote administration turned on, were id...
FBI: End-of-life routers hacked for cybercrime proxy networks
BleepingComputer
·Bill Toulas
·Published May 8, 2025
·Updated
Affected Software
4 affected components
LinkSys router
Cisco router
LinkSys router
Cisco router
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the FBI's warning about hackers exploiting end-of-life routers to create cybercrime proxy networks.
2
What security implications are discussed in the article?
The article highlights the risk of end-of-life routers being compromised and used for malicious activities without user awareness.
3
What products or software are affected by the malware?
The affected products include older Linksys and Cisco routers that no longer receive security updates.
4
Why are end-of-life routers vulnerable to hacking?
End-of-life routers are vulnerable because they do not receive security updates, making them easy targets for hackers.
5
What networks are mentioned as being utilized for cybercrime in the article?
The article mentions the 5Socks and Anyproxy networks as platforms where compromised routers are sold as proxies.