Look for unusual self-signed certificates, repeated service fingerprints across distant IP addresses, unexpected remote-access exposure, and devices that continue to communicate normally while behaving as shared infrastructure. Those signals suggest a campaign that is trying to stay hidden inside ordinary network traffic.
What makes router relay activity look different from ordinary networking?
A compromised router used as a relay usually still appears “up” and functional, which is why the compromise can sit inside normal traffic for some time. The signs come from mismatches: certificates that do not fit the environment, fingerprints that repeat across unrelated locations, and access paths that exist where they were never expected. The pattern is often stealth, not disruption.
Which indicators matter most when a router becomes shared infrastructure?
The strongest indicators are behavioural and infrastructural together. A self-signed or otherwise unusual certificate can point to an operator trying to terminate or redirect traffic without relying on trusted public PKI. Repeated service fingerprints across distant IP addresses suggest one control point or tooling stack is being reused at scale. Unexpected remote-access exposure, especially on devices that should not be internet-facing, is another serious warning.
Just as important is the “looks normal, acts as a relay” pattern. If the device continues to pass legitimate traffic while also hosting services, proxying sessions, or exposing admin surfaces, it may be functioning as a shared hop rather than a clean network edge. That dual behaviour is what makes this class of compromise easy to miss.
For a broader view of how compromise patterns, stolen access material, and lateral movement show up in real incidents, The State of NHI & AI Agent Breach Report 2026 is useful background on the abuse chain operators tend to build once they gain durable access.
How should responders separate relay abuse from a one-off misconfiguration?
Context is the key discriminator. A single unusual certificate or an isolated exposed management port may be a hardening gap; the same sign across multiple routers, or paired with repeated fingerprints and consistent remote-access behaviour, is much more likely to indicate deliberate relay infrastructure. Investigators should look for reuse, scale, and persistence rather than a single noisy artifact.
That distinction matters because relay abuse usually aims to preserve deniability. The attacker does not need obvious outages if the device can quietly forward traffic, hide source locations, or provide a stable bridge into other systems. The compromise is often validated by the fact that the router still “works” from the owner’s perspective while serving someone else’s pathing objectives.
Risk and Threat Considerations
Router relay activity creates exposure because the device can become an invisible transit point for malicious traffic, credential theft, scanning, or command-and-control. The security risk is not only that the router is compromised, but that it can lend legitimacy to traffic that appears to originate from ordinary infrastructure.
Failure mechanism: the attacker keeps the router operational enough to avoid attention while repurposing it as a relay, proxy, or pivot point. Reused fingerprints, exposed remote management, and abnormal certificate use help the operator blend into routine network behaviour.
Impact: defenders can lose source attribution, miss lateral movement, and allow malicious sessions to persist longer than they would if the device were noisy or obviously broken. The relay can also widen blast radius by providing a stable path into internal services or across geographically separated targets.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1090 — Proxy | Relay routers function as proxy infrastructure to hide source and route traffic. |
| T1219 — Remote Access Software | Unexpected remote-access exposure can indicate persistent operator control over a router. | |
| Recommendation — Map relay-like behaviour to Proxy and hunt for hidden transit infrastructure. Look for unauthorized remote-access tooling on network devices and isolate exposed hosts. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and network services are monitored to find potential cybersecurity events | Router relay signs depend on monitoring unusual certificates, fingerprints, and exposure. |
| PR.AA-05 — Access permissions, entitlements, and authorizations are managed | Unexpected management exposure reflects weak authorization over device access paths. | |
| Recommendation — Monitor router-facing services for certificate, fingerprint, and exposure anomalies. Restrict router admin access to approved management paths and accounts. | ||
| NIST SP 800-53 Rev 5 | AC-3 — Access Enforcement | Compromised routers used as relays exploit weak enforcement over management and transit paths. |
| Recommendation — Enforce access restrictions on router management and relay-capable services. | ||
Practitioner Guidance
What to prioritise: Treat certificate anomalies, remote-access exposure, and repeated service fingerprints as a single investigation thread, not three separate curiosities. If they co-occur on the same device or across a small cluster, escalate quickly.
What to verify: Confirm whether management interfaces are supposed to be reachable at all, whether the presented certificate chain matches your approved build, and whether the same device identity is appearing from multiple distant source locations. That combination is much more actionable than any one signal alone.
What good looks like: legitimate routers have tightly bounded admin exposure, stable and expected service identity, and no unexplained role as a transit point for unrelated traffic. When those conditions are absent, assume the box may be serving a purpose beyond routing.
Practitioner takeaway: The most dangerous relay compromise is the one that preserves normal availability while quietly changing the device’s trust role, so investigate identity, exposure, and traffic reuse together rather than waiting for outages or obvious malware signs.