Researchers uncover “self-sustaining” botnets of poorly secured routers
Home and small office devices are free for the taking, ensuring follow-on hacks. — Large numbers of home and small-office routers are under the control of hackers who are using them to overwhelm websites …
Context & Ripple Effects
This 2015 report is the opening move in a decade-long arc the related coverage traces end to end. Months later, researchers found a highly stealthy backdoor infecting Cisco routers across at least four countries, with dozens more devices surfacing in a follow-up sweep — evidence that the compromise wasn't a one-off campaign but standing infrastructure.
What changed since: by 2017, a vigilante actor had concluded cleanup was impossible and started destroying the hardware outright (BrickerBot bricked poorly secured Linux-based routers and IoT devices), while Trend Micro later documented cybercriminals and nation-state spies coexisting inside the same compromised name-brand routers. The 2015 insight — that these devices are free for the taking and enable follow-on hacks — turned out to be the durable operating condition of consumer networking gear.
First-order effects
- Owners of compromised home and small-office routers lose control of their bandwidth and processing to operators launching DDoS floods against websites, typically without any visible sign on the device.
Second-order effects
- Defenders concluded that disinfection fails: BrickerBot's answer was to deliberately brick infected routers rather than clean them, forcing owners to replace hardware — and turning the same pool of weak devices into contested ground where botnet builders and vigilantes compete for control.
Third-order effects
- If the pattern holds — and the 2024 Trend Micro finding of criminals and state spies sharing one box suggests it has — the consumer router stops being trusted infrastructure entirely, with persistence engineered to survive reboots and updates as the baseline attacker requirement.
The trend: Consumer routers have shifted from occasional attack targets to permanently contested multi-tenant infrastructure, with each wave of research showing deeper persistence and more actors on the same devices.