The FBI Found Criminals Running Traffic Through Your Router. Here Is What Dayton Businesses Need to Know.

by | Apr 8, 2026 | Cybersecurity, Networking

Home  ›  Blog  ›  Current Post

The FBI Found Criminals Running Traffic Through Your Router
Security Alert

The FBI Found Criminals Running Traffic Through Your Router. Here Is What Dayton Businesses Need to Know.

April 08, 2026 FBI FLASH Alert 20260312-001 DaytonABS

On March 12, 2026, the FBI published a FLASH alert confirming that hundreds of thousands of small office and home routers had been quietly infected with malware and turned into criminal infrastructure. The operation ran for years without most device owners having any idea. If your router has not been replaced recently, this is worth five minutes of your time.

A criminal group built a service called SocksEscort. They used malware called AVrecon to break into routers at homes and small businesses, then sold access to those compromised connections to other criminals. The criminals who bought access could route their illegal activity through your IP address, making it look like it came from your office network.

369,000 Devices compromised since 2020
163 Countries affected
2,500+ US routers active at takedown
$3.5M Cryptocurrency frozen

SocksEscort customers used those stolen connections to commit:

Banking Fraud Romance Scams Ad Fraud Password Spraying Digital Marketplace Fraud Website Exploitation

To any security system watching, that activity appeared to originate from ordinary home and business internet addresses.

The FBI, Europol, and law enforcement partners in France, the Netherlands, and Austria coordinated the takedown. Law enforcement seized 34 domains and shut down 23 servers across seven countries. The SocksEscort service has been disrupted. The malware may still be present on infected devices.

AVrecon does not need you to click anything. It spreads by scanning the internet for routers with known, unpatched vulnerabilities. The attack methods include Remote Code Execution (RCE), command injection, and weaknesses in SOAP interfaces found in many small business router management panels.

Once it finds a vulnerable router, it installs itself silently. Your internet continues to work normally. Most people never notice anything is wrong.

After installation, the malware contacts its command server every 60 seconds. When a command comes in, it can direct your router to open a traffic tunnel for a SocksEscort customer, download and run additional malicious code, or give the attacker a direct remote shell into your device.

AVrecon is written to be lightweight and hard to detect. Routers do not run antivirus software. There is no endpoint agent watching for it. That is exactly why attackers went after them.

The FBI identified 18 router models that appeared most frequently in the confirmed infection data. Check the label on the bottom of your router and compare it against this list.

D-Link
  • DIR-818LW Wireless Router
  • DIR-850L Wireless Router
  • DIR-860L Wireless Router
Netgear
  • DGN2200v4 Wireless Router
  • AC1900 R7000
TP-Link
  • Archer C20 Wireless Router
  • TL-WR840N Wireless Router
  • TL-WR849N Wireless Router
  • WR841N Wireless Router
Zyxel
  • EMG6726-B10A Router
  • PMG5617GA Home Gateway Unit
  • VMG1312-B10D Wireless Router
  • VMG1312-T20B Wireless Router
  • VMG3925-B10A Wireless Router
  • VMG3925-B10C Wireless Router
  • VMG4825-B10A Wireless Router
  • VMG4927-B50A Wireless Router
  • VMG8825-T50K Wireless Router
Not on the list does not mean safe. The FBI noted AVrecon targets approximately 1,200 device models from multiple manufacturers. These 18 are the routers seen most often in confirmed infections. If your router is older and not listed here, it was not in the top 18. That is not a clean bill of health.

This is the part I want to make sure is clear, because it is the part most people get wrong.

On some infected routers, the attackers used the device's own built-in firmware update feature to flash a custom firmware image. That image contains a hardcoded copy of AVrecon. It also disables the device's ability to accept future updates or be reflashed. Those routers are, for practical purposes, permanently infected. A factory reset does nothing. The malware survives it.

On other models, AVrecon does not install a persistence mechanism. A power cycle clears the infection. But the FBI documented at least one case where AVrecon's command servers detected the loss of an infected device and automatically re-infected it using the same vulnerability that allowed the original compromise. Rebooting without patching the underlying flaw just gives the attacker another shot at the same door.

If your router model is on the list above, treat it as compromised and plan to replace it.

If your router is not on the list but is several years old, check the manufacturer's website and look up the end-of-life date for your specific model. End-of-life devices no longer receive security patches. That is exactly what made these routers attractive targets. A router that does not get updates is a router waiting to be compromised the same way.

For any router you plan to keep in service, do these four things:

  1. 1 Log into the admin panel and apply any available firmware update.
  2. 2 Disable remote management if you do not actively use it. This closes one of the most common entry points.
  3. 3 Change the default admin credentials if you have not already.
  4. 4 Watch for warning signs: unusual spikes in data usage, slower performance with no clear cause, or devices on your network you do not recognize.

If your router is on the list or is end-of-life, those steps are not a permanent fix. Replacement is the answer.

I see this pattern constantly with small and mid-sized businesses in the Dayton area. Security attention goes toward the obvious stuff: the workstations, the servers, the Microsoft 365 accounts. The router sits in the corner and nobody thinks about it because the internet keeps working.

That is exactly the blind spot this operation exploited. Criminals specifically targeted SOHO routers because they know those devices go years without updates, they have no endpoint protection running on them, and most business owners never check them.

A compromised router means criminal traffic is moving through your business IP address. Depending on what that traffic is used for, it can create legal exposure, trigger fraud flags with your bank or payment processor, or get your IP address blacklisted by services your business depends on every day.

It also means an attacker has persistent remote access to the device that sits between your business and the internet. That is not a minor issue.

Not Sure About Your Router?

If you are not sure what router you have, whether it is current, or whether your network has any of these exposures, reach out. I work with Dayton-area businesses on exactly this kind of thing: making sure the hardware running your network is current, maintained, and not leaving easy entry points open.

We offer a free 30-minute technology review for new clients.

Free 30-minute tech review for new clients

Sources

  • FBI FLASH Alert 20260312-001, March 12, 2026 (ic3.gov)
  • SecurityWeek: Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
  • The Cyber Express: FBI Warns of AVrecon Malware Targeting Network Devices
  • HS Today: FBI Warns AVrecon Malware Compromised 369,000 Routers Worldwide

Filed under: All Posts

About the Author

David Pfiffner is the owner of Dayton Allied Business Solutions, a managed IT and web solutions company serving businesses in the Huber Heights and Dayton, Ohio area. Nearly two decades of hands-on technology experience.

Need IT Help?

Proactive IT management, cybersecurity, backup, and web solutions for Dayton businesses. Flat monthly pricing. Local support.

Explore the Blog

Browse all posts for practical technology tips, IT advice, and web strategy for small businesses in the Dayton area.

Ready to Put This Into Practice?

If something in this post resonated, let’s talk. We work with small businesses in the Dayton area on exactly these kinds of problems.

Special Offer!

Get a free 30-minute review of your IT setup. We look at what you have, tell you what is at risk, and give you one thing you can do today at no cost and no obligation.

Grab the Offer!