Home routers are always on and rarely checked, which makes them ideal recruits.
Published October 2026 · ismyroutersafe.com
A botnet is a network of hacked devices that an attacker controls remotely. Home routers are frequent targets. US government advisories from 2016 to 2025 describe router botnets used for attacks, spying and hiding criminals’ traffic. The ones below were built from routers with default passwords, unpatched flaws or no support.
What is a botnet?
The FBI and NSA describe it as a network of devices infected with malware that gives attackers unauthorized remote access. It can deliver malware, launch denial-of-service attacks or route criminal traffic.
Your router keeps working. It just also works for someone else.
From the team behind this checker
Want a router that takes this seriously by default?
SecureRooms. Smart devices live apart from your computers.
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site and grades its own router by the same method.
How routers get recruited
Default passwords. CISA says Mirai used a list of 62 common default logins. The FBI and NSA say Moobot, based on Mirai, spreads through weak or default passwords.
Known flaws. The Flax Typhoon-linked botnet used known vulnerability exploits, per the FBI and NSA. TheMoon needs no password at all, the FBI says.
End-of-life routers. The Justice Department says the vast majority of KV botnet routers were end-of-life Cisco and NetGear models.
What router botnets are used for
Knocking sites offline. CISA says Mirai hit a security journalist’s blog with an attack over 620 gigabits per second in 2016.
Hiding hackers. The Justice Department says Volt Typhoon used hacked home and small office routers to conceal the China-based origin of its hacking.
Renting out your connection. The FBI says criminals installed proxies on hacked routers so others could commit crimes anonymously.
Spying. The FBI and NSA say Russian state actors used hacked routers to harvest credentials and host phishing pages.
Botnets the US has warned about
Mirai (2016). Large attacks mostly using home routers, cameras and video recorders, per CISA.
VPNFilter (2018). Hundreds of thousands of home and office routers and networked devices compromised worldwide, per the FBI.
KV botnet (2023 to 2024). A court-authorized FBI operation removed it from hundreds of US routers used by Volt Typhoon.
Moobot and APT28 (2024). Russian military intelligence used hacked routers for spying, per the FBI and NSA.
Flax Typhoon-linked botnet (2024). Over 260,000 devices as of June 2024, run by a China-based company with government links.
TheMoon proxies (2025). A new variant hit end-of-life routers with remote administration on, per the FBI.
Often you cannot tell. The FBI said VPNFilter’s use of encryption made its activity hard to detect. It lists overheating, connection problems and unrecognized setting changes as common signs. See hacked router signs.
How to stay out of a botnet
Update the firmware, automatically where offered.
Replace default passwords with strong, unique ones.
Turn off remote management and UPnP unless you need them. The FBI says attackers abuse them.
Reboot weekly, as the NSA recommends. Some malware lives only in memory.
Separate smart devices, as the FBI and NSA advise.
Replace end-of-life routers with supported models.
Yes. The FBI and NSA said many devices in a 2024 botnet of 260,000 were likely still supported by their makers. Supported routers still need updates installed and default passwords changed.
Sometimes. CISA says Mirai lives in memory, so a reboot clears it, but reinfection can be quick if the password is not changed. For some hacked routers, the FBI and NSA advise a factory reset and firmware update.
The FBI notified owners of infected routers during its court-authorized operation, or asked internet providers to pass on notice. The Justice Department said the vast majority were end-of-life Cisco and NetGear routers.
Both criminals and governments. US advisories describe botnets run by criminal proxy services, Russian military intelligence, and a China-based company linked to Flax Typhoon.
Report it to the FBI’s Internet Crime Complaint Center at ic3.gov. The Justice Department also points to CISA’s online reporting.
Sources
Dates show when each source was published or when we checked it.