Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Agencies Dismantle SocksEscort Proxy Network

Global Agencies Dismantle SocksEscort Proxy Network

Posted on March 13, 2026 By CWS

Authorities from the United States and Europe have successfully dismantled SocksEscort, a notorious proxy service linked to various cybercriminal activities. This service enabled users to conceal their online identities and bypass security protocols, facilitating crimes such as DDoS attacks, ransomware campaigns, and the dissemination of illegal content.

Impact of SocksEscort on Cybersecurity

According to reports from Europol and the US Justice Department, SocksEscort was driven by a network of compromised routers and IoT devices. Since 2020, approximately 363,000 IP addresses across 163 countries have been associated with this illicit service. By February 2026, just before the enforcement action, around 8,000 hacked routers were part of this network, with 2,500 based in the United States.

The disruption was supported by Lumen Technologies’ Black Lotus Labs, which revealed that SocksEscort affected an average of 20,000 unique victims weekly. These activities were managed through about 15 command-and-control nodes, highlighting the extensive reach of the operation.

Financial and Operational Details

Financially, the proxy service generated over $5.7 million from its users. Information from the US Justice Department suggests that many participants reaped significant profits, engaging in fraudulent activities that victimized individuals to the tune of hundreds of thousands, and in some cases, up to $1 million. Law enforcement agencies managed to seize 34 domains and 23 servers across seven countries, while the United States froze $3.5 million in cryptocurrency assets related to the operation.

The infected modems, which were integral to maintaining the proxy service, have been disconnected. This step marks a significant blow to the infrastructure that supported SocksEscort’s operations.

Technical Aspects and Future Outlook

The FBI has issued a warning about the AVrecon malware, which was used to power SocksEscort. The service operators exploited known vulnerabilities in routers and IoT devices to deploy this malware, forming a botnet. AVrecon targeted approximately 1,200 device models from manufacturers like Cisco, D-Link, and Netgear, primarily affecting small-office/home-office routers through vulnerabilities such as Remote Code Execution and command injection.

In response, the agency has disseminated information on the malware’s distribution and provided security recommendations. This effort follows a broader trend of international cooperation in combating cybercrime, as seen with recent actions against platforms like Tycoon 2FA.

The takedown of SocksEscort underscores the ongoing challenges in cybersecurity and highlights the importance of collaborative efforts among global agencies to combat cyber threats effectively. As authorities continue to address these issues, the focus remains on securing devices and preventing future exploits.

Security Week News Tags:AVrecon, Botnet, Cybercrime, Cybersecurity, Europol, FBI, IoT security, law enforcement, proxy service, SocksEscort

Post navigation

Previous Post: Google Urgently Updates Chrome to Fix Exploited Flaws
Next Post: Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud

Related Posts

Google Ships Android ‘Advanced Protection’ Mode to Thwart Surveillance Spyware Google Ships Android ‘Advanced Protection’ Mode to Thwart Surveillance Spyware Security Week News
From Open Source to OpenAI: The Evolution of Third-Party Risk From Open Source to OpenAI: The Evolution of Third-Party Risk Security Week News
 Million Worth of Bitcoin Seized in Cryptomixer Takedown $29 Million Worth of Bitcoin Seized in Cryptomixer Takedown Security Week News
Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Security Week News
Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play Security Week News
In Other News: LockBit 5.0, Department of War Cybersecurity Framework, OnePlus Vulnerability In Other News: LockBit 5.0, Department of War Cybersecurity Framework, OnePlus Vulnerability Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Onyx Security Secures $40 Million to Enhance AI Control
  • Google Patches Chrome Zero-Day Vulnerabilities in Skia and V8
  • Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud
  • Global Agencies Dismantle SocksEscort Proxy Network
  • Google Urgently Updates Chrome to Fix Exploited Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Onyx Security Secures $40 Million to Enhance AI Control
  • Google Patches Chrome Zero-Day Vulnerabilities in Skia and V8
  • Salesforce Issues Alert on ShinyHunters Threat to Experience Cloud
  • Global Agencies Dismantle SocksEscort Proxy Network
  • Google Urgently Updates Chrome to Fix Exploited Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News