Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Posted on March 13, 2026 By CWS

An international coalition of law enforcement agencies has successfully dismantled the SocksEscort proxy network, a criminal enterprise that exploited residential routers worldwide. This sophisticated operation, authorized by the courts, targeted a botnet that had enlisted thousands of these devices to facilitate large-scale fraudulent activities.

SocksEscort’s Extensive Reach

The U.S. Department of Justice revealed that SocksEscort infected internet routers with malware, enabling it to route internet traffic through compromised devices. This access was then sold to customers, allowing them to disguise their online activities. Since its emergence in 2020, SocksEscort offered access to approximately 369,000 IP addresses across 163 countries, with a significant concentration of affected routers in the United States.

Operating under the guise of selling “static residential IPs with unlimited bandwidth,” SocksEscort’s service was designed to bypass spam blocklists, offering sizable proxy packages at various price points. Its ultimate objective was to obscure the true location and identity of its users, facilitating criminal acts without detection.

Impact and Investigation

The investigation into SocksEscort uncovered a range of victims, including a New York-based cryptocurrency exchange customer defrauded of $1 million and a Pennsylvania manufacturing business that lost $700,000. Military personnel were also targeted, with $100,000 stolen from MILITARY STAR cardholders.

The operation, dubbed Operation Lightning, was coordinated by Europol and involved law enforcement from multiple countries, including the U.S., Austria, and Germany. The crackdown resulted in the shutdown of 34 domains and 23 servers in seven countries, alongside the freezing of $3.5 million in cryptocurrency assets.

Technical Details and Threats

Key to SocksEscort’s functionality was the AVrecon malware, actively exploited since at least May 2021. This malware targeted around 1,200 device models, including those from Cisco and D-Link, using vulnerabilities like Remote Code Execution. The FBI noted the malware’s ability to permanently infect devices by modifying firmware to ensure persistent access.

AVrecon allowed attackers to control infected devices remotely and execute various payloads, effectively turning them into proxies for criminal purposes. This capability made SocksEscort a significant threat, particularly as it was marketed exclusively to malicious actors.

In conclusion, the dismantling of the SocksEscort botnet marks a significant victory in the fight against cybercrime. Authorities continue to monitor such threats, emphasizing the importance of securing internet-connected devices to prevent future exploitation.

The Hacker News Tags:AVrecon, Cybercrime, Cybersecurity, Europol, FBI, internet security, law enforcement, Malware, proxy botnet, SocksEscort

Post navigation

Previous Post: Veeam Fixes Critical Flaws in Backup Software
Next Post: Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Related Posts

Watch This Webinar to Uncover Hidden Flaws in Login, AI, and Digital Trust — and Fix Them Watch This Webinar to Uncover Hidden Flaws in Login, AI, and Digital Trust — and Fix Them The Hacker News
Why Executives and Practitioners See Risk Differently Why Executives and Practitioners See Risk Differently The Hacker News
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries The Hacker News
Helping CISOs Speak the Language of Business Helping CISOs Speak the Language of Business The Hacker News
AI Becomes Russia’s New Cyber Weapon in War on Ukraine AI Becomes Russia’s New Cyber Weapon in War on Ukraine The Hacker News
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Onyx Security Secures $40 Million to Enhance AI Control
  • Google Patches Chrome Zero-Day Vulnerabilities in Skia and V8
  • Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud
  • Global Agencies Dismantle SocksEscort Proxy Network
  • Google Urgently Updates Chrome to Fix Exploited Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Onyx Security Secures $40 Million to Enhance AI Control
  • Google Patches Chrome Zero-Day Vulnerabilities in Skia and V8
  • Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud
  • Global Agencies Dismantle SocksEscort Proxy Network
  • Google Urgently Updates Chrome to Fix Exploited Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News