Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Posted on March 13, 2026 By CWS

An international coalition of law enforcement agencies has successfully dismantled the SocksEscort proxy network, a criminal enterprise that exploited residential routers worldwide. This sophisticated operation, authorized by the courts, targeted a botnet that had enlisted thousands of these devices to facilitate large-scale fraudulent activities.

SocksEscort’s Extensive Reach

The U.S. Department of Justice revealed that SocksEscort infected internet routers with malware, enabling it to route internet traffic through compromised devices. This access was then sold to customers, allowing them to disguise their online activities. Since its emergence in 2020, SocksEscort offered access to approximately 369,000 IP addresses across 163 countries, with a significant concentration of affected routers in the United States.

Operating under the guise of selling “static residential IPs with unlimited bandwidth,” SocksEscort’s service was designed to bypass spam blocklists, offering sizable proxy packages at various price points. Its ultimate objective was to obscure the true location and identity of its users, facilitating criminal acts without detection.

Impact and Investigation

The investigation into SocksEscort uncovered a range of victims, including a New York-based cryptocurrency exchange customer defrauded of $1 million and a Pennsylvania manufacturing business that lost $700,000. Military personnel were also targeted, with $100,000 stolen from MILITARY STAR cardholders.

The operation, dubbed Operation Lightning, was coordinated by Europol and involved law enforcement from multiple countries, including the U.S., Austria, and Germany. The crackdown resulted in the shutdown of 34 domains and 23 servers in seven countries, alongside the freezing of $3.5 million in cryptocurrency assets.

Technical Details and Threats

Key to SocksEscort’s functionality was the AVrecon malware, actively exploited since at least May 2021. This malware targeted around 1,200 device models, including those from Cisco and D-Link, using vulnerabilities like Remote Code Execution. The FBI noted the malware’s ability to permanently infect devices by modifying firmware to ensure persistent access.

AVrecon allowed attackers to control infected devices remotely and execute various payloads, effectively turning them into proxies for criminal purposes. This capability made SocksEscort a significant threat, particularly as it was marketed exclusively to malicious actors.

In conclusion, the dismantling of the SocksEscort botnet marks a significant victory in the fight against cybercrime. Authorities continue to monitor such threats, emphasizing the importance of securing internet-connected devices to prevent future exploitation.

The Hacker News Tags:AVrecon, Cybercrime, Cybersecurity, Europol, FBI, internet security, law enforcement, Malware, proxy botnet, SocksEscort

Post navigation

Previous Post: Veeam Fixes Critical Flaws in Backup Software
Next Post: Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Related Posts

OpenClaw AI Vulnerabilities Pose Security Threats OpenClaw AI Vulnerabilities Pose Security Threats The Hacker News
New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters The Hacker News
How to Gain Control of AI Agents and Non-Human Identities How to Gain Control of AI Agents and Non-Human Identities The Hacker News
Cross-App Permissions: Unseen Risks and Solutions Cross-App Permissions: Unseen Risks and Solutions The Hacker News
Compromised Update Impacts Smart Slider 3 Pro Plugin Compromised Update Impacts Smart Slider 3 Pro Plugin The Hacker News
How Smart MSSPs Using AI to Boost Margins with Half the Staff How Smart MSSPs Using AI to Boost Margins with Half the Staff The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Target Pharma Firms with Malware
  • EU Pushes Google to Share Anonymized User Data
  • Google Patches Critical Gemini CLI Vulnerability
  • ClickUp’s API Key Leak Exposes Fortune 500 Emails
  • New Fast16 Malware Uncovered: Cybersecurity Concerns Rise

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Target Pharma Firms with Malware
  • EU Pushes Google to Share Anonymized User Data
  • Google Patches Critical Gemini CLI Vulnerability
  • ClickUp’s API Key Leak Exposes Fortune 500 Emails
  • New Fast16 Malware Uncovered: Cybersecurity Concerns Rise

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark