SDMmag logo
search
Go to Ask SDM AI
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
SDMmag logo
  • NEWS
  • PRODUCTS
  • TOPICS
    • Access Control & Identification
    • Integration & Network Solutions
    • Life Safety & Fire Alarm
    • Monitoring
    • Smart Home
    • Trends & Industry Issues
    • Video Solutions
  • COLUMNS
    • Digital Shuffle
    • Editor's Angle
    • Insider News & Business
    • Integration Spotlight
    • Marketing Madmen
    • Security & the Law
    • Security Comings & Goings
    • Security Networkings
    • Technology @ Work
    • Technology Solutions & Skills
    • SIA Waypoints
    • Cybersecurity Chronicle
  • EXCLUSIVES
    • Annual Industry Forecast
    • Dealer of the Year
    • Project of the Year
    • SDM 100
    • State of the Market Series
    • Systems Integrator of the Year
    • Top Systems Integrator Report
    • TMA Excellence Awards
  • BLOG
  • MEDIA
    • Videos
    • Podcasts
    • Polls
    • White Papers
  • EVENTS
    • Industry Calendar
    • Webinars
  • MORE
    • Classified Ads
    • Newsletters
    • SDM Store
    • State of Security eBook
    • Sponsored Insights
  • BUYERS GUIDE
    • Buyers Guide
    • Take a Tour
  • EMAG
    • eMagazine
    • Archive Issues
    • Monitoring Today
    • Advertise
  • SIGN UP!
Integration & Network Solutions

Sponsored Content

Notorious Botnet Has Resurfaced to Exploit End-of-Life Routers & IoT Devices

Router
May 8, 2024

A recent report by Black Lotus Labs, a security research team at Lumen Technologies, has revealed a multi-year campaign aimed at vulnerable small home/small office (SOHO) routers. This campaign exploits an upgraded iteration of the notorious malware strain known as “TheMoon.”


Since its inception in 2014, TheMoon malware has consistently exploited vulnerabilities in routers and Internet of Things (IoT) devices. However, this recent campaign seems exceptionally pervasive, as it has infected devices in 88 countries.


The Black Lotus Labs report, titled “The Darkside Of TheMoon,” indicates that the attackers concentrated mainly on end-of-life (EoL) routers, which are devices no longer receiving security updates from the manufacturer. ASUS routers bore the brunt of this focus, with over 6,000 infections occurring within a mere 72-hour period in early March 2024.


The attackers seem to aim at establishing an extensive network of compromised devices. By infiltrating routers and IoT devices, they enlist them into a service dubbed “Faceless.” This service functions as a proxy, enabling malicious actors to obscure their online actions. Such anonymity poses challenges in tracing the origins of cyberattacks and other illicit operations.


“The attackers behind Faceless are using the botnets from this malware to create an anonymous proxy network by abusing outdated and unsupported routers to run their criminal networks,” said Mark Dehus, senior director of threat intelligence at Lumen Black Lotus Labs. “We believe these cybercriminals are using these networks to steal data and information from their victims, including the financial sector.”


The selection of EoL appliances as targets for building the botnet is no coincidence, as these devices lack manufacturer support and gradually become vulnerable to security risks. Additionally, they may be compromised through brute-force attacks.


Further examination of the proxy network indicates that over 30 percent of the infections persisted for more than 50 days, while approximately 15 percent of the devices remained within the network for 48 hours or less.

Looking for quick answers on security topics? Try Ask SDM, our new smart AI search tool. Ask SDM →


Black Lotus Labs believes TheMoon is the main or sole provider of bots to Faceless. This proxy service gives its users the chance to impersonate a legitimate user in a chosen country. Faceless doesn’t require customer identification. This allows users to stay anonymous as they send malicious traffic through the routers attempting to steal valuable data.

“TheMoon malware is a serious threat not only to the owners of the compromised SOHO devices, but also the victims exploited through this anonymous proxy network,” Dehus cautions. Users are urged to update and secure their devices to prevent them from becoming part of these malicious networks, he added.


Strategies for Prevention and Mitigation


Installing security contractors can advise their consumer and commercial clients to take these steps to protect their routers from cybercriminals:


  • Reboot: Consumers who use SOHO routers should regularly reboot their devices and install security updates and patches when available.
  • Update old routers: Consumers and business should replace end-of-life devices with vendor-supported models to help ensure security updates are in place.


IT professionals can take these steps:


  • Install protection: Remote workers can invite threats to a company network. Install Web Application Firewalls to protect company assets from communicating with bots.
  • Monitor activity: Look for suspicious login attempts, even those that come from residential IP addresses.
  • Encrypt data: Use the latest cryptographic protocols, such as TLS (Transport Layer Security) to encrypt data sent over the internet. This helps secure email and website services.

According to Lumen, this is not the first instance of infected devices being enrolled into a proxy service, and it is a growing trend. The company said it suspects that with the increased attention paid to the cybercrime ecosystem by both law enforcement and intelligence organizations, criminals are looking for new methods to obscure their activity.

KEYWORDS: router

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
to unlock your recommendations.

Already have an account? Sign In

  • SDM 100

    SDM 100: Top 100 Security Dealers of 2026

    The top 100 security dealers navigated a complex...
    SDM 100 Report
    By: Karyn Hodgson
  • Security camera

    State of the Market: Video Surveillance

    As video surveillance shifts from siloed systems to...
    Video Solutions
    By: Brianna Wilson
  • 2026 Industry Forecast

    SDM 2026 INDUSTRY FORECAST

    Rapid technology advances meet shifting economic...
    Exclusives
    By: Karyn Hodgson
Manage My Account
  • SDM Newsletters
  • Online Registration
  • eMagazine Subscriptions
  • Subscription Customer Service
  • Manage My Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the SDM audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of SDM or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Doctor examining child patient with mother present in medical clinic
    Sponsored byHID

    The Human Side of Hospital Security: How Modern Visitor Management Protects People First

Popular Stories

Video surveillance camera

Why Video Health Monitoring Is a ‘No Brainer’

ESA Board of Directors Q2 26 Elections

Electronic Security Association Announces 2026 Board of Directors Election Results

TMA & SDM Logos

Becklar, Elite & Puget Win 2026 TMA/SDM Monitoring Center Excellence Awards

SDM Dealer of the Year 2026 Promotion

Poll

What’s the most promising trend in the industry?

What’s the most promising trend in the industry?
View Results Poll Archive

Products

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

See More Products
SDM 100 2026 Rankings
×

Be in the forefront of security intelligence when you receive SDM.

Join over 10,000+ professionals when you subscribe today.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Directories
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing