Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Authorities takedown global proxy network SocksEscort  – CyberScoop
AttackFeed by Joe Wagner | Authorities takedown global proxy network SocksEscort  - CyberScoop

Authorities takedown global proxy network SocksEscort  – CyberScoop

Posted on March 12, 2026 By Matt Kapko
Attack Feeds

Authorities from multiple countries dismantled SocksEscort, a residential proxy network cybercriminals used to commit large-scale fraud, claiming access to about 369,000 IP addresses since 2020, the Justice Department said Thursday.

Europol, which aided the investigation alongside various law enforcement agencies, Lumen’s Black Lotus Labs and the Shadowserver Foundation, said the malicious proxy service compromised routers and IoT devices in 163 countries. Officials said the proxy network’s payment platform received about $5.8 million from its customers.

The globally coordinated action, dubbed Operation Lightning, took down and seized 34 domains and 23 servers in seven countries. U.S. officials froze a combined $3.5 million in cryptocurrency allegedly linked to the botnet that was created from infected devices.

“Cybercrime thrives on anonymity,” Catherine De Bolle, executive director at Europol, said in a statement. “Proxy services like SocksEscort provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection.”

SocksEscort’s operators assembled the botnet by exploiting a vulnerability in residential modems from an unnamed vendor, according to officials.

The cybercrime operation defrauded Americans and U.S. businesses of millions of dollars, the Justice Department said. More than one-quarter of the 8,000 infected routers SocksEscort advertised in February were based in the United States.  

SocksEscort began operating in 2009 and its command-and-control infrastructure went undetected by most tools for a very long time, Ryan English, information security engineer at Black Lotus Labs, told CyberScoop.

The botnet’s infrastructure, which was powered by AVRecon malware, was elusive and maintained a consistently high volume, claiming an average 20,000 victims weekly since early 2024. Its impact peaked in January 2025 when it ensnared more than 15,000 victims daily, according to Black Lotus Labs’ research. 

The company said it observed 280,000 unique IPs as victims of the proxy network since early 2025, and more than half of SocksEscort’s victims were based in the United States and United Kingdom.

“Given the high volume of victim generation, it would not surprise me if they eventually hit something really important that moved them up the list of networks to go after,” Chris Formosa, senior lead information security engineer at Black Lotus Labs, told CyberScoop. 

“They were exclusively marketing to cybercriminals and nowhere else,” he added. “With a network like this, once law enforcement gains legal access to backend infrastructure it can give them a lot of intelligence on other threat actors besides the botnet operators.”

Various agencies from Austria, Bulgaria, Eurojust, France, Germany, Hungary, the Netherlands and Romania assisted in the investigation and takedown.

The post Authorities takedown global proxy network SocksEscort appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Officials worry Salt Typhoon apathy is killing momentum for tougher telecom security rules  – CyberScoop
Next Post: Announcing Pwn2Own Berlin for 2026  – Zero Day Initiative – Blog ❯

You may also like

AttackFeed by Joe Wagner | Inside Department 4: Russia’s secret school for hackers  - GRAHAM CLULEY
Attack Feeds
Inside Department 4: Russia’s secret school for hackers  – GRAHAM CLULEY
May 8, 2026
AttackFeed by Joe Wagner | Malicious npm Package Stole Files From Claude AI User Directory via GitHub  - The Hacker News
Attack Feeds
Malicious npm Package Stole Files From Claude AI User Directory via GitHub  – The Hacker News
May 27, 2026
AttackFeed by Joe Wagner | Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 13, 2026
AttackFeed by Joe Wagner | TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials  - The Hacker News
Attack Feeds
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials  – The Hacker News
March 24, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.