
Network for Rent: The Criminal Market Built on Outdated Routers
About this episode
Cybercriminals are exploiting outdated routers to build massive proxy networks that hide malware operations, fraud, and credential theft—right under the radar of enterprise defenses. In this episode, Sherri and Matt unpack the FBI’s May 2025 alert, the role of TheMoon malware, and how the Faceless proxy service industrializes anonymity for hire. Learn how these botnets work, why they matter for your enterprise, and what to do next.
Takeaways
- Replace outdated routers End-of-life routers should be identified and replaced across your organization, including remote offices and unmanaged home setups. These devices no longer receive patches and are prime targets for compromise.
- Restrict remote administration If remote access is needed, tightly control it—limit by IP address, use VPN access, and require MFA. Avoid exposing admin interfaces directly to the internet unless absolutely necessary.
- Patch and harden infrastructure Apply all available firmware updates and follow vendor security guidance. Where possible, segment or monitor legacy network devices that can’t be immediately replaced.
- Don’t trust domestic IPs Traffic from domestic or residential IP ranges is no longer inherently safe. Compromised routers make malicious activity appear to come from trusted regions.
- Add proxy abuse to threat intel Incorporate indicators of compromise from Lumen and FBI alerts into detection rulesets. Treat proxy abuse as a key TTP for credential theft, fraud, and malware C2.
- Report suspected compromise If you identify affected infrastructure or suspicious traffic, report it to IC3.gov. Include IPs, timestamps, device types, and any supporting forensic detail.
#CybersideChats #Cybersecurity #Tech #Cyber #CyberAware #CISO #CIO #FBIalert #FBIwarning #Malware #Router
Get every episode summarized
Each time Cyberside Chats: Cybersecurity Insights from the Experts publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from Cyberside Chats: Cybersecurity Insights from the Experts

AI Collusion? Inside the OpenAI–Hugging Face Attack
Cyberside Chats: Cybersecurity Insights from the Experts

Your Security Tools Can Be Used Against You
Cyberside Chats: Cybersecurity Insights from the Experts

Zoomsday: Anyone in Your Meeting Can Own You
Cyberside Chats: Cybersecurity Insights from the Experts

AI vs. AI: Hacking the Agent, Not the Human
Cyberside Chats: Cybersecurity Insights from the Experts