Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Agencies Dismantle SocksEscort Proxy Network

Global Agencies Dismantle SocksEscort Proxy Network

Posted on March 13, 2026 By CWS

Authorities from the United States and Europe have successfully dismantled SocksEscort, a notorious proxy service linked to various cybercriminal activities. This service enabled users to conceal their online identities and bypass security protocols, facilitating crimes such as DDoS attacks, ransomware campaigns, and the dissemination of illegal content.

Impact of SocksEscort on Cybersecurity

According to reports from Europol and the US Justice Department, SocksEscort was driven by a network of compromised routers and IoT devices. Since 2020, approximately 363,000 IP addresses across 163 countries have been associated with this illicit service. By February 2026, just before the enforcement action, around 8,000 hacked routers were part of this network, with 2,500 based in the United States.

The disruption was supported by Lumen Technologies’ Black Lotus Labs, which revealed that SocksEscort affected an average of 20,000 unique victims weekly. These activities were managed through about 15 command-and-control nodes, highlighting the extensive reach of the operation.

Financial and Operational Details

Financially, the proxy service generated over $5.7 million from its users. Information from the US Justice Department suggests that many participants reaped significant profits, engaging in fraudulent activities that victimized individuals to the tune of hundreds of thousands, and in some cases, up to $1 million. Law enforcement agencies managed to seize 34 domains and 23 servers across seven countries, while the United States froze $3.5 million in cryptocurrency assets related to the operation.

The infected modems, which were integral to maintaining the proxy service, have been disconnected. This step marks a significant blow to the infrastructure that supported SocksEscort’s operations.

Technical Aspects and Future Outlook

The FBI has issued a warning about the AVrecon malware, which was used to power SocksEscort. The service operators exploited known vulnerabilities in routers and IoT devices to deploy this malware, forming a botnet. AVrecon targeted approximately 1,200 device models from manufacturers like Cisco, D-Link, and Netgear, primarily affecting small-office/home-office routers through vulnerabilities such as Remote Code Execution and command injection.

In response, the agency has disseminated information on the malware’s distribution and provided security recommendations. This effort follows a broader trend of international cooperation in combating cybercrime, as seen with recent actions against platforms like Tycoon 2FA.

The takedown of SocksEscort underscores the ongoing challenges in cybersecurity and highlights the importance of collaborative efforts among global agencies to combat cyber threats effectively. As authorities continue to address these issues, the focus remains on securing devices and preventing future exploits.

Security Week News Tags:AVrecon, Botnet, Cybercrime, Cybersecurity, Europol, FBI, IoT security, law enforcement, proxy service, SocksEscort

Post navigation

Previous Post: Google Urgently Updates Chrome to Fix Exploited Flaws
Next Post: Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud

Related Posts

Tidal Cyber Raises  Million for CTI and Adversary Behavior Platform Tidal Cyber Raises $10 Million for CTI and Adversary Behavior Platform Security Week News
Pentagon’s AI Dispute with Anthropic Over Autonomy Pentagon’s AI Dispute with Anthropic Over Autonomy Security Week News
Ex-WhatsApp Security Chief Sues Meta Over Vulnerabilities, Retaliation Ex-WhatsApp Security Chief Sues Meta Over Vulnerabilities, Retaliation Security Week News
New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages New Sturnus Banking Trojan Targets WhatsApp, Telegram, Signal Messages Security Week News
‘MadeYouReset’ HTTP2 Vulnerability Enables Massive DDoS Attacks ‘MadeYouReset’ HTTP2 Vulnerability Enables Massive DDoS Attacks Security Week News
Companies Warned of Commvault Vulnerability Exploitation Companies Warned of Commvault Vulnerability Exploitation Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Bold Security Unveils $40 Million Funding Round
  • Starbucks Phishing Attack Compromises Employee Data
  • Google Awards $17 Million in 2025 Bug Bounty Payouts
  • Linux AppArmor Vulnerabilities Risk Root Escalation
  • Critical Security Update Addresses Veeam RCE Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Bold Security Unveils $40 Million Funding Round
  • Starbucks Phishing Attack Compromises Employee Data
  • Google Awards $17 Million in 2025 Bug Bounty Payouts
  • Linux AppArmor Vulnerabilities Risk Root Escalation
  • Critical Security Update Addresses Veeam RCE Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News