Trend Micro: cybercriminals and nation-state spies are coexisting inside the same compromised name-brand routers, using the devices to disguise their attacks
How and why nation-state hackers and cybercriminals coexist in the same router botnet. — Cybercriminals and spies working …
Context & Ripple Effects
Router compromise has long supported durable botnets: researchers previously documented self-sustaining botnets of poorly secured routers, while separate reporting identified stealthy router backdoors affecting Cisco devices. Trend Micro’s finding matters because it shows those devices can be shared infrastructure rather than the exclusive asset of one operator.
The overlap also fits later coverage of nation-state actors using home-device software to build residential proxy networks that mask attack traffic. Shared router access makes the boundary between criminal and state-linked traffic less useful for defenders trying to identify an operation from its network path.
First-order effects
- Owners of the compromised routers become involuntary relay points for multiple threat actors, increasing the volume and variety of malicious traffic associated with their devices.
- Investigators and network defenders lose a simple attribution signal: traffic emerging from a known botnet may serve criminal activity and espionage at the same time.
Second-order effects
- Router vendors, ISPs, and enterprise security teams face pressure to prioritize remediation and monitoring of edge devices, since cleaning one device can disrupt several operators’ access paths.
- Criminal and state-linked groups can benefit from the same pool of residential-looking infrastructure, lowering the need for each group to independently build traffic-masking capacity.
Third-order effects
- If shared access persists, compromised consumer networking gear may operate increasingly like a contested, multi-tenant proxy layer—making infrastructure-based blocking and attribution less decisive.
- The pattern strengthens the case for ecosystem-wide cyber defense across device makers, service providers, and threat researchers, rather than treating router infections as isolated consumer-security incidents.
The trend: Compromised home and edge devices are becoming reusable infrastructure that can blur the operational boundary between financially motivated cybercrime and state espionage.