The FBI Found Criminals Running Traffic Through Your Router. Here Is What Dayton Businesses Need to Know.
On March 12, 2026, the FBI published a FLASH alert confirming that hundreds of thousands of small office and home routers had been quietly infected with malware and turned into criminal infrastructure. The operation ran for years without most device owners having any idea. If your router has not been replaced recently, this is worth five minutes of your time.
What Happened
A criminal group built a service called SocksEscort. They used malware called AVrecon to break into routers at homes and small businesses, then sold access to those compromised connections to other criminals. The criminals who bought access could route their illegal activity through your IP address, making it look like it came from your office network.
SocksEscort customers used those stolen connections to commit:
To any security system watching, that activity appeared to originate from ordinary home and business internet addresses.
The FBI, Europol, and law enforcement partners in France, the Netherlands, and Austria coordinated the takedown. Law enforcement seized 34 domains and shut down 23 servers across seven countries. The SocksEscort service has been disrupted. The malware may still be present on infected devices.
How the Malware Got In
AVrecon does not need you to click anything. It spreads by scanning the internet for routers with known, unpatched vulnerabilities. The attack methods include Remote Code Execution (RCE), command injection, and weaknesses in SOAP interfaces found in many small business router management panels.
Once it finds a vulnerable router, it installs itself silently. Your internet continues to work normally. Most people never notice anything is wrong.
AVrecon is written to be lightweight and hard to detect. Routers do not run antivirus software. There is no endpoint agent watching for it. That is exactly why attackers went after them.
The Router List
The FBI identified 18 router models that appeared most frequently in the confirmed infection data. Check the label on the bottom of your router and compare it against this list.
- DIR-818LW Wireless Router
- DIR-850L Wireless Router
- DIR-860L Wireless Router
- DGN2200v4 Wireless Router
- AC1900 R7000
- Archer C20 Wireless Router
- TL-WR840N Wireless Router
- TL-WR849N Wireless Router
- WR841N Wireless Router
- EMG6726-B10A Router
- PMG5617GA Home Gateway Unit
- VMG1312-B10D Wireless Router
- VMG1312-T20B Wireless Router
- VMG3925-B10A Wireless Router
- VMG3925-B10C Wireless Router
- VMG4825-B10A Wireless Router
- VMG4927-B50A Wireless Router
- VMG8825-T50K Wireless Router
Why Rebooting Is Not Enough
This is the part I want to make sure is clear, because it is the part most people get wrong.
On some infected routers, the attackers used the device's own built-in firmware update feature to flash a custom firmware image. That image contains a hardcoded copy of AVrecon. It also disables the device's ability to accept future updates or be reflashed. Those routers are, for practical purposes, permanently infected. A factory reset does nothing. The malware survives it.
What to Do Now
If your router model is on the list above, treat it as compromised and plan to replace it.
If your router is not on the list but is several years old, check the manufacturer's website and look up the end-of-life date for your specific model. End-of-life devices no longer receive security patches. That is exactly what made these routers attractive targets. A router that does not get updates is a router waiting to be compromised the same way.
For any router you plan to keep in service, do these four things:
- 1 Log into the admin panel and apply any available firmware update.
- 2 Disable remote management if you do not actively use it. This closes one of the most common entry points.
- 3 Change the default admin credentials if you have not already.
- 4 Watch for warning signs: unusual spikes in data usage, slower performance with no clear cause, or devices on your network you do not recognize.
If your router is on the list or is end-of-life, those steps are not a permanent fix. Replacement is the answer.
Why This Matters for Small Businesses
I see this pattern constantly with small and mid-sized businesses in the Dayton area. Security attention goes toward the obvious stuff: the workstations, the servers, the Microsoft 365 accounts. The router sits in the corner and nobody thinks about it because the internet keeps working.
That is exactly the blind spot this operation exploited. Criminals specifically targeted SOHO routers because they know those devices go years without updates, they have no endpoint protection running on them, and most business owners never check them.
A compromised router means criminal traffic is moving through your business IP address. Depending on what that traffic is used for, it can create legal exposure, trigger fraud flags with your bank or payment processor, or get your IP address blacklisted by services your business depends on every day.
It also means an attacker has persistent remote access to the device that sits between your business and the internet. That is not a minor issue.
Not Sure About Your Router?
If you are not sure what router you have, whether it is current, or whether your network has any of these exposures, reach out. I work with Dayton-area businesses on exactly this kind of thing: making sure the hardware running your network is current, maintained, and not leaving easy entry points open.
We offer a free 30-minute technology review for new clients.
Sources
- FBI FLASH Alert 20260312-001, March 12, 2026 (ic3.gov)
- SecurityWeek: Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
- The Cyber Express: FBI Warns of AVrecon Malware Targeting Network Devices
- HS Today: FBI Warns AVrecon Malware Compromised 369,000 Routers Worldwide
