FBI Warned of Compromised Legacy Routers Used in Botnets

Threat actors are hijacking abandoned, unpatched home hardware to mask malicious traffic as legitimate residential activity.

Updated on Oct. 2, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized router with cables connecting to a dark conduit, representing compromised residential infrastructure.
The FBI warned that threat actors are exploiting unpatched, legacy home routers to host proxy nodes for criminal activities, masking malicious traffic as residential. AI Illustration. Upload story photo >

Live Poll

Is now a good time to replace your old home network routers to improve security?

The FBI issued a warning regarding the exploitation of end-of-life routers that no longer receive security patches. Cybercriminals are hijacking this legacy hardware to host residential proxy nodes for illicit activities.

Why it matters

Criminals use compromised residential IP addresses to bypass automated security filters, making malicious traffic appear as if it originates from a standard home connection. This tactic effectively weaponizes consumer infrastructure to facilitate phishing, credential stuffing, and DDoS attacks.

Attackers gain root access by exploiting vulnerable remote management daemons—background software processes that handle router configuration—often left active on devices that have not received a manufacturer firmware patch in five years.

The players

FBI

The domestic intelligence and security service of the United States responsible for investigating cyber threats and issuing public safety advisories.

Linksys

A networking hardware company known for its consumer-grade routers, including legacy models like the E1000, E1200, and E2500.

The details

Threat actors scan for older router models that remain exposed to the internet with default or unpatched remote management features. Once access is established, the router is integrated into a proxy-as-a-service botnet. This allows criminals to tunnel malicious traffic through the home network, effectively anonymizing the source of cyberattacks by hiding them behind a residential IP address.

Timeline

  1. October 2, 2026: FBI issued the official warning concerning compromised routers.

  2. Past five years: Period during which affected legacy devices have not received security patches.

The Tech Race

This development follows the precedent set by the 2016 Mirai botnet attack, which demonstrated how insecure IoT devices could be repurposed for massive network disruption. It marks a persistent shift where residential hardware becomes the frontline for anonymizing global cybercrime.

Homeowners using routers that have not received firmware updates for several years should replace the hardware immediately, as these devices lack the protections against modern exploit vectors. Running legacy equipment poses a risk of having your home connection identified as a source of criminal traffic during investigations.

The takeaway

Legacy hardware is a permanent security liability that attackers will continue to prioritize for its lack of defensive updates. Check your router model's support status and transition to a device that still receives active security patches to avoid becoming a proxy for criminal botnets.

Further reading

For broader context on current network threats, see our Cybersecurity section.

Source note: This article includes information reported by XDA-Developers.

Live Poll

Is now a good time to replace your old home network routers to improve security?