Listen to this Post

Introduction:
In a sweeping international crackdown dubbed “Operation Moonlander,” law enforcement agencies have dismantled a massive botnet that has silently infected routers worldwide for over two decades. This covert network fueled two underground proxy services, Anyproxy and 5socks, providing cover for cybercriminal operations across the globe. With the U.S. Department of Justice leading the charge, this unprecedented operation exposes how outdated devices, cybercrime-for-hire services, and lax network security became the perfect storm for a \$46 million criminal enterprise. The takedown marks a significant victory in the ongoing war against cybercrime, but it also reveals a dark truth: outdated technology continues to be a key vulnerability in our digital world.
Key Developments and Core Insights:
A botnet operating since 2004 infected thousands of outdated routers to build two residential proxy networks: Anyproxy and 5socks.
These proxy services enabled anonymity for cybercriminals involved in ad fraud, DDoS attacks, brute-force intrusions, and data theft.
U.S. authorities indicted four individuals: three Russian nationals and one Kazakhstani for running and profiting from these illegal platforms.
The botnet used variants of TheMoon malware to infect routers, particularly targeting Linksys and Cisco devices nearing or past their end-of-life (EoL).
Users of the proxy services paid between \$9.95 and \$110 monthly, depending on service tier.
Investigations revealed that malware-infected routers were sold as legitimate residential IPs on proxy marketplaces, making cybercriminal traffic harder to detect.
Only around 10% of these proxies were flagged as malicious by tools like VirusTotal, showing a sophisticated method of evading detection.
Servers involved in the infrastructure were hosted globally, including in Russia, the Netherlands, Türkiye, and the U.S.
Authorities worked with global agencies including Dutch National Police, the Royal Thai Police, and analysts from Black Lotus Labs.
The FBI issued a public warning urging immediate replacement or patching of vulnerable routers still in use.
The infected routers were exploited without authentication and often left with remote administration enabled—magnifying the risk.
The conspiracy resulted in over \$46 million in illicit gains and prolonged the viability of the botnet by using legitimate-looking residential traffic.
Charges include conspiracy to commit computer fraud and abuse, and false domain registration, among others.
The dismantled sites—Anyproxy.net and 5socks.net—promoted access to over 7,000 proxy nodes.
The botnet infrastructure had roots in JCS Fedora Communications, a known Russian hosting service.
Residual malware activity suggests many infected routers may still be operational or at risk.
U.S. prosecutors have labeled this case as one of the most persistent and evasive cybercrime infrastructures to date.
What Undercode Say:
The takedown of the Anyproxy and 5socks botnet is more than just a cybercrime bust—it’s a wake-up call for individuals and corporations alike. What made this botnet particularly insidious wasn’t just its longevity, but its method: leveraging outdated hardware, exploiting weak configurations, and masquerading under the guise of residential traffic. This allowed it to thrive virtually undetected for two decades.
From a technical standpoint, the usage of TheMoon malware was strategic. The malware specifically targeted routers with open remote administration—a common setting for older devices. These routers, often neglected in terms of firmware updates or patching, became low-hanging fruit for cybercriminals. Once infected, they were not only used as proxies but also served as entry points into wider networks.
What’s striking is the scale of deception. By creating a marketplace for “legitimate” residential IP proxies, the perpetrators effectively created a veil for malicious actors to conduct attacks with little fear of detection. Most security systems trust residential traffic over data center IPs, and this trust was skillfully exploited.
The fact that only 10% of the malicious traffic was flagged by tools like VirusTotal underscores how ineffective traditional detection methods can be against well-camouflaged threats. The implication here is significant: companies relying solely on signature-based detection are vulnerable to stealthy botnet-driven proxies.
Furthermore, the economic model was simple yet highly profitable. With monthly subscriptions ranging from \$10 to over \$100, and thousands of customers, the operation netted tens of millions in revenue. This points to a robust demand for anonymizing services among cybercriminals, emphasizing the ongoing challenge of regulating gray-market proxy services.
Legally, the indictment sends a strong message. The charges not only cover unauthorized computer access but also domain name fraud—a tactic often overlooked in cybercrime investigations. This comprehensive legal approach could set a precedent for future operations.
International cooperation also played a vital role. Cybercrime knows no borders, and the collaboration between U.S., Dutch, Thai, and private sector partners shows the kind of multi-agency response needed to dismantle entrenched cybercriminal infrastructures.
However, the story doesn’t end with the takedown. Many routers remain infected, especially among users unaware their devices are compromised. This leaves open the possibility of the botnet’s remnants being reactivated or repurposed. The FBI’s advisory highlights a larger systemic issue: a lack of public awareness and corporate responsibility around network hygiene.
In essence, the dismantling of this botnet is a technical victory—but the war is far from over. Education, regulation, and proactive security policies are needed to prevent similar networks from rising again. As long as outdated devices remain online and unpatched, the door remains open to cybercriminals.
Fact Checker Results:
Verified international collaboration involving the U.S., Netherlands, and Thailand.
Confirmed use of TheMoon malware targeting end-of-life routers.
Documented income of over \$46 million from proxy service subscriptions.
Prediction:
Given the scale and stealth of the Anyproxy and 5socks operations, future cybercriminal groups may increasingly mimic this model—targeting unpatched consumer-grade hardware to build proxy networks masked as legitimate residential traffic. We expect a surge in legislation around consumer router security, broader adoption of AI-driven anomaly detection tools, and heightened scrutiny of proxy marketplaces. Security vendors will likely prioritize innovations that distinguish between genuine residential traffic and botnet-generated anonymity cloaks.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.quora.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




