• News/
  • https://www.bleepingcomputer.com/news/security/fbi-end-of-life-routers-hacked-for-cybercrime-proxy-networks/

FBI: End-of-life routers hacked for cybercrime proxy networks

BleepingComputer
·
Bill Toulas
·
Published May 8, 2025
·
Updated

The FBI warns that threat actors are deploying malware on end-of-life (EoL) routers to convert them into proxies sold on the 5Socks and Anyproxy networks. These devices, which were released many years back and no longer receive security updates from their vendors, are vulnerable to external attacks leveraging publicly available exploits to inject persistent malware. Once compromised, they are added to residential proxy botnets that route malicious traffic. In many cases, these proxies are used by cybercriminals to conduct malicious activities or cyberattacks. "With the 5Socks and Anyproxy network, criminals are selling access to compromised routers as proxies for customers to purchase and use," explains the FBI Flash advisory. "The proxies can be used by threat actors to obfuscate their identity or location." The advisory lists the following EoL Linksys and Cisco models as common targets: The FBI warns that Chinese state-sponsored actors have exploited known (n-day) vulnerabilities in these routers to conduct covert espionage campaigns, including operations targeting critical U.S. infrastructure. In a related bulletin, the agency confirms that many of these routers are infected with a variant of the "TheMoon" malware, which enables threat actors to configure them as proxies. "End of life routers were breached by cyber actors using variants of TheMoon malware botnet," reads the FBI bulletin. "Recently, some routers at end of life, with remote administration turned on, were id...

Read full article

Affected Software

4 affected components
LinkSys router
Cisco router
LinkSys router
Cisco router
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the FBI's warning about hackers exploiting end-of-life routers to create cybercrime proxy networks.

2

What security implications are discussed in the article?

The article highlights the risk of end-of-life routers being compromised and used for malicious activities without user awareness.

3

What products or software are affected by the malware?

The affected products include older Linksys and Cisco routers that no longer receive security updates.

4

Why are end-of-life routers vulnerable to hacking?

End-of-life routers are vulnerable because they do not receive security updates, making them easy targets for hackers.

5

What networks are mentioned as being utilized for cybercrime in the article?

The article mentions the 5Socks and Anyproxy networks as platforms where compromised routers are sold as proxies.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203