Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Global Crackdown Dismantles SocksEscort Proxy Botnet Network

Posted on March 13, 2026 By CWS

An international coalition of law enforcement agencies has successfully dismantled the SocksEscort proxy network, a criminal enterprise that exploited residential routers worldwide. This sophisticated operation, authorized by the courts, targeted a botnet that had enlisted thousands of these devices to facilitate large-scale fraudulent activities.

SocksEscort’s Extensive Reach

The U.S. Department of Justice revealed that SocksEscort infected internet routers with malware, enabling it to route internet traffic through compromised devices. This access was then sold to customers, allowing them to disguise their online activities. Since its emergence in 2020, SocksEscort offered access to approximately 369,000 IP addresses across 163 countries, with a significant concentration of affected routers in the United States.

Operating under the guise of selling “static residential IPs with unlimited bandwidth,” SocksEscort’s service was designed to bypass spam blocklists, offering sizable proxy packages at various price points. Its ultimate objective was to obscure the true location and identity of its users, facilitating criminal acts without detection.

Impact and Investigation

The investigation into SocksEscort uncovered a range of victims, including a New York-based cryptocurrency exchange customer defrauded of $1 million and a Pennsylvania manufacturing business that lost $700,000. Military personnel were also targeted, with $100,000 stolen from MILITARY STAR cardholders.

The operation, dubbed Operation Lightning, was coordinated by Europol and involved law enforcement from multiple countries, including the U.S., Austria, and Germany. The crackdown resulted in the shutdown of 34 domains and 23 servers in seven countries, alongside the freezing of $3.5 million in cryptocurrency assets.

Technical Details and Threats

Key to SocksEscort’s functionality was the AVrecon malware, actively exploited since at least May 2021. This malware targeted around 1,200 device models, including those from Cisco and D-Link, using vulnerabilities like Remote Code Execution. The FBI noted the malware’s ability to permanently infect devices by modifying firmware to ensure persistent access.

AVrecon allowed attackers to control infected devices remotely and execute various payloads, effectively turning them into proxies for criminal purposes. This capability made SocksEscort a significant threat, particularly as it was marketed exclusively to malicious actors.

In conclusion, the dismantling of the SocksEscort botnet marks a significant victory in the fight against cybercrime. Authorities continue to monitor such threats, emphasizing the importance of securing internet-connected devices to prevent future exploitation.

The Hacker News Tags:AVrecon, Cybercrime, Cybersecurity, Europol, FBI, internet security, law enforcement, Malware, proxy botnet, SocksEscort

Post navigation

Previous Post: Veeam Fixes Critical Flaws in Backup Software
Next Post: Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Related Posts

How to Browse the Web More Sustainably With a Green Browser How to Browse the Web More Sustainably With a Green Browser The Hacker News
Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed The Hacker News
Critical Cisco Flaws Fixed: IMC and SSM Security Updates Critical Cisco Flaws Fixed: IMC and SSM Security Updates The Hacker News
Critical MLflow and FUXA Vulnerabilities Exploited by Attackers Critical MLflow and FUXA Vulnerabilities Exploited by Attackers The Hacker News
Cybercrime Group Recruits Women for IT Vishing Cybercrime Group Recruits Women for IT Vishing The Hacker News
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark