Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Posted on March 13, 2026 By CWS

An international coalition of law enforcement agencies has successfully dismantled the SocksEscort proxy network, a criminal enterprise that exploited residential routers worldwide. This sophisticated operation, authorized by the courts, targeted a botnet that had enlisted thousands of these devices to facilitate large-scale fraudulent activities.

SocksEscort’s Extensive Reach

The U.S. Department of Justice revealed that SocksEscort infected internet routers with malware, enabling it to route internet traffic through compromised devices. This access was then sold to customers, allowing them to disguise their online activities. Since its emergence in 2020, SocksEscort offered access to approximately 369,000 IP addresses across 163 countries, with a significant concentration of affected routers in the United States.

Operating under the guise of selling “static residential IPs with unlimited bandwidth,” SocksEscort’s service was designed to bypass spam blocklists, offering sizable proxy packages at various price points. Its ultimate objective was to obscure the true location and identity of its users, facilitating criminal acts without detection.

Impact and Investigation

The investigation into SocksEscort uncovered a range of victims, including a New York-based cryptocurrency exchange customer defrauded of $1 million and a Pennsylvania manufacturing business that lost $700,000. Military personnel were also targeted, with $100,000 stolen from MILITARY STAR cardholders.

The operation, dubbed Operation Lightning, was coordinated by Europol and involved law enforcement from multiple countries, including the U.S., Austria, and Germany. The crackdown resulted in the shutdown of 34 domains and 23 servers in seven countries, alongside the freezing of $3.5 million in cryptocurrency assets.

Technical Details and Threats

Key to SocksEscort’s functionality was the AVrecon malware, actively exploited since at least May 2021. This malware targeted around 1,200 device models, including those from Cisco and D-Link, using vulnerabilities like Remote Code Execution. The FBI noted the malware’s ability to permanently infect devices by modifying firmware to ensure persistent access.

AVrecon allowed attackers to control infected devices remotely and execute various payloads, effectively turning them into proxies for criminal purposes. This capability made SocksEscort a significant threat, particularly as it was marketed exclusively to malicious actors.

In conclusion, the dismantling of the SocksEscort botnet marks a significant victory in the fight against cybercrime. Authorities continue to monitor such threats, emphasizing the importance of securing internet-connected devices to prevent future exploitation.

The Hacker News Tags:AVrecon, Cybercrime, Cybersecurity, Europol, FBI, internet security, law enforcement, Malware, proxy botnet, SocksEscort

Post navigation

Previous Post: Veeam Fixes Critical Flaws in Backup Software
Next Post: Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Related Posts

Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine Russian Hackers Gamaredon and Turla Collaborate to Deploy Kazuar Backdoor in Ukraine The Hacker News
CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation CISA Orders Immediate Patch of Critical Sitecore Vulnerability Under Active Exploitation The Hacker News
Google Patches Critical Zero-Day Flaw in Chrome’s V8 Engine After Active Exploitation Google Patches Critical Zero-Day Flaw in Chrome’s V8 Engine After Active Exploitation The Hacker News
Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account The Hacker News
Critical Flaw in MCP Protocol Poses Major AI Supply Chain Risk Critical Flaw in MCP Protocol Poses Major AI Supply Chain Risk The Hacker News
Why Built-In Protections Aren’t Enough for Modern Data Resilience Why Built-In Protections Aren’t Enough for Modern Data Resilience The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISOs Shift Budget to BAS Amid AI Vulnerability Surge
  • Critical Splunk Vulnerability Enables Remote Code Execution
  • Worm Code Breach and AI Risks Highlight Cyber Threats
  • Cybersecurity Stars Awards 2026: 95 Winners Revealed
  • Gentlemen Ransomware Hits 478, Spreads Like a Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark