Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What happens when attackers turn compromised routers into…
Cyber Security

What happens when attackers turn compromised routers into command-and-control infrastructure?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

When attackers convert routers into command-and-control infrastructure, they gain a durable platform for relaying commands, staging tools, and hiding the true source of malicious activity. That makes blocking harder and extends dwell time. Defenders may see scattered traces on downstream systems while the router itself becomes the control point coordinating theft, backdoors, or additional exploitation.

Why Compromised Routers Become Such Effective Control Points

A router is valuable to attackers because it sits on a traffic chokepoint and can relay, filter, or disguise command traffic without having to compromise every downstream host. Once the device is repurposed, the attacker can issue instructions through infrastructure that already looks operationally normal, which makes simple source-blocking less effective and gives the campaign a more durable coordination layer.

The key shift is not just that the router is “infected”, but that it becomes part of the attacker’s operational infrastructure. That lets the adversary centralise command delivery, proxy activity through a trusted path, and keep control even when individual payloads, hosts, or accounts are remediated. For defenders, that means the observable symptoms often appear far from the real control point.

That pattern is one reason device compromise is so disruptive in practice. A compromised router can also support staging, redirection, and persistence, so the attacker is no longer dependent on a single endpoint being available. NHIMG’s The 52 NHI breaches Report is a useful companion for understanding how compromised infrastructure and stolen access material repeatedly become operational leverage in real incidents.

How Attackers Use the Router in the Attack Chain

Once the router is under attacker control, it can serve several functions at once. It may proxy command-and-control traffic, relay stolen data, host lightweight tooling, or forward requests to other compromised systems. In some cases, it also helps conceal the true origin of operations by making the traffic appear to come from ordinary residential or enterprise network infrastructure.

This matters because defenders may only see fragments: unusual outbound connections, brief bursts of traffic, or secondary compromise on internal systems. The router can sit between initial compromise and later actions such as theft, backdoor management, lateral movement, or follow-on exploitation. That makes the campaign harder to attribute and slower to disrupt.

The operational value is similar across many abuse patterns: once an attacker owns a stable intermediary, they can reuse it for multiple objectives. 52 NHI Breaches Analysis shows the same basic lesson across breach cases, which is that compromised control material tends to be reused for persistence, lateral movement, and repeat access rather than a single isolated action. For broader threat-context on active adversary behaviour, CISA cyber threat advisories remains a strong reference point.

What Defenders Should Verify Before Treating the Router as “Just a Device”

In practice, a compromised router should be treated as a trust failure, not a nuisance cleanup item. If the device is still reachable by the attacker, rotating downstream passwords alone may not be enough, because the router may still be able to redirect traffic, observe sessions, or re-establish control paths. Recovery has to include confirming the device state, its configuration integrity, and whether it is part of a wider compromise set.

The most useful verification questions are straightforward: has the router been factory-reset or re-imaged, are admin credentials and remote-management settings known to be clean, and is there evidence of persistence in configuration, firmware, or adjacent management systems? If those answers are incomplete, the device cannot be assumed safe just because business traffic appears normal again.

What to verify: confirm the router is not only reachable, but actually restored to a trusted baseline; check for unauthorized DNS, forwarding, remote-management, and tunnelling settings; and look for unexplained command relay or traffic redirection that would indicate the device is still serving the attacker.

Practitioner takeaway: The real risk is not the compromised router itself, but the attacker control plane it enables, so remediation has to break that control relationship rather than only clean up downstream symptoms.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1090 — ProxyCompromised routers are often used to relay and obscure attacker traffic.
T1095 — Non-Application Layer ProtocolRouters may carry covert command traffic over network-layer channels.
T1573 — Encrypted ChannelAttackers commonly hide control traffic in encrypted tunnels through compromised infrastructure.
Recommendation — Map router relay activity to T1090 and hunt for proxy-like command traffic. Inspect for abnormal non-application-layer traffic that can carry command and control. Review encrypted outbound paths for hidden command and control use.
NIST CSF 2.0DE.CM — Security Continuous MonitoringThis scenario depends on detecting abnormal traffic and compromised device behaviour.
PR.AC — Identity Management, Authentication and Access ControlRouter compromise frequently starts with weak administrative access and poor access control.
RS.AN — AnalysisIncident response must determine whether the router is a relay, persistence point, or both.
Recommendation — Monitor router behaviour and outbound patterns for signs of infrastructure abuse. Restrict router administration to tightly controlled, authenticated management paths. Analyze router compromise to identify attacker reach, persistence, and control paths.
CIS Controls v84 — Secure Configuration of Enterprise Assets and SoftwareCompromised routers usually involve insecure or altered device configuration.
6 — Access Control ManagementAttackers rely on excessive or weak administrative access to take over routers.
13 — Network Monitoring and DefenseThe core detection problem is spotting malicious relay and redirection activity.
Recommendation — Enforce hardened router baselines and verify configuration integrity after any compromise. Limit router administrative access and remove any unnecessary management exposure. Monitor network paths for unusual relay, tunnelling, and command-and-control patterns.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org