Cyber Criminal Proxy Services Exploiting End of Life Routers


The Federal Bureau of Investigation (FBI) is issuing this announcement to inform individuals and businesses about proxy services taking advantage of end of life routers that are susceptible to vulnerabilities. When a hardware device is end of life, the manufacturer no longer sells the product and is not actively supporting the hardware, which also means they are no longer releasing software updates or security patches for the device.

Routers dated 2010 or earlier likely no longer receive software updates issued by the manufacturer and could be compromised by cyber actors exploiting known vulnerabilities. End of life routers were breached by cyber actors using variants of TheMoon malware botnet. Recently, some routers at end of life, with remote administration turned on, were identified as compromised by a new variant of TheMoon malware. This malware allows cyber actors to install proxies on unsuspecting victim routers and conduct cyber crimes anonymously.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Swiss government says SharePoint-linked data breach affected hundreds of accounts

    August 7, 2026

    Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation. In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal ...

  • Apple’s Private Relay tool can leak users’ IP addresses

    August 6, 2026

    WebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the IP addresses of users who paid to keep them hidden. This is according to security researchers Talal Haj Bakry and Tommy Mysk who noted they had found “three WebKit features that bypass the proxy configuration and send traffic directly from the ...

  • TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices

    August 5, 2026

    TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE). Security researchers at Vedere Labs from Forescout found the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business ...

  • Cybercriminals allegedly hacked tens of thousands of Fortinet firewalls used by major companies all over the world

    June 17, 2026

    Cybercriminals have compromised tens of thousands of Fortinet firewalls and VPNs used by major companies all over the world, according to two cybersecurity firms. The widespread hacking campaign, which is ongoing and has been dubbed FortiBleed, appears to not involve abusing any unknown vulnerability in the targeted devices, but rather on a more basic issue: Companies ...

  • CISA gives US federal agencies three days to fix a VPN bug under attack by a ransomware gang

    June 9, 2026

    A ransomware group is actively exploiting an unpatched flaw in security tools used across the U.S. federal government, prompting the U.S. cybersecurity agency CISA to order all civilian agencies to remediate the vulnerability by end of day Wednesday. Cybersecurity firm Check Point Software said the bug affects several of its remote access tools, firewalls, and VPNs, which act as ...

  • Palo Alto VPN bug graduates from advisory to active exploitation

    June 1, 2026

    Palo Alto customers are being been told to patch yet another internet-facing security flaw after researchers caught attackers bypassing GlobalProtect authentication and gaining unauthorized VPN access. The flaw, tracked as CVE-2026-0257, affects PAN-OS deployments using GlobalProtect authentication override cookies under specific configurations. Read more… Source:  The Register Sign up for the Cyber Security Review Newsletter The latest cyber security news and ...