• News/
  • https://www.theregister.com/2025/05/10/router_botnet_crashed/

End-of-life router botnet shut, 4 'foreign hackers' charged

The Register
·
Iain Thomson
·
Published May 10, 2025
·
Updated

Earlier this week, the FBI urged folks to bin aging routers vulnerable to hijacking, citing ongoing attacks linked to TheMoon malware. In a related move, the US Department of Justice unsealed indictments against four foreign nationals accused of running a long-running proxy-for-hire network that exploited outdated routers to funnel criminal traffic. In a FLASH bulletin [PDF] on Wednesday, the FBI warned that aging routers from Linksys and Cisco, commonly found in homes and small businesses, were being actively targeted by cybercriminals. These devices, long past their update window, were compromised and made available for sale as part of a criminal proxy network marketed through the 5socks and Anyproxy domains. The botnet provided anonymity to malicious users and enabled a range of cybercrime, including distributed denial of service (DDoS) attacks, according to federal investigators and security researchers. Here are the dusty old routers you need to watch out for: A DoJ indictment issued on Friday offered more details on how the botnets allegedly operated. The operators charged between $9.95 and $110 per month for access to what they claimed were over 7,000 residential proxies, the indictment claims. Prosecutors believe the scheme pulled in more than $46 million, with the website boasting it had been "Working since 2004!" Not anymore, since the domain running the attacks has been seized in what the Feds are calling Operation Moonlander. You've been pwned- Click to enlarge A ...

Read full article

Affected Software

5 affected components
LinkSys router
Cisco router
ASUS router
LinkSys router
Cisco router
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What prompted the FBI to advise users to dispose of certain routers?

The FBI urged users to dispose of aging routers due to vulnerabilities that made them susceptible to hijacking, particularly linked to TheMoon malware.

2

What is the name of the malware associated with the router attacks?

The malware associated with the router attacks is called TheMoon.

3

What actions were taken against the individuals responsible for these router attacks?

The US Department of Justice unsealed indictments against four foreign nationals charged with involvement in the router attacks.

4

Which brands of routers are specifically mentioned as affected?

The affected router brands mentioned include Linksys, Cisco, and Asus.

5

What is the significance of the indictments announced by the US Department of Justice?

The indictments underscore international efforts to combat cyber crime and hold hackers accountable for compromising network security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203