The US Department of Justice announced the shutdown of the Russian malware botnet RSocks, which is used to hijack millions of computers, Android smartphones, and IoT (Internet of Things) devices worldwide for use as proxy servers.
See also: New Go botnet Panchan spreads rapidly across educational networks

The law enforcement operation involved the FBI and police forces in Germany, the Netherlands , and the United Kingdom, where the botnet maintained parts of its infrastructure.
A botnet is a swarm of devices that threat actors can control remotely to perform various behaviors, including DDoS attacks, crypto mining , and the deployment of additional malware.
In the case of RSocks, the botnet was used to turn home computers into proxy servers, allowing botnet clients to use for malicious activity or to appear as coming from a home IP.

See also: Botnet XLoader: Hides its servers using probability theory
Typical usage scenarios for these services include phishing operations , credential stuffing , account takeover attempts , etc. Furthermore, using a proxy service makes it more difficult for law enforcement to track threat actors, especially when these IP addresses belong to people who are unaware their devices were seized .
RSocks was also promoted for use by shopping bots, such as sneaker bots, which benefit from using residential IP addresses, which are typically not banned by online retailers.
A secret investigation
FBI agents began mapping the RSocks infrastructure to an undercover operation where they purchased access to a large number of proxies in 2017.
According to the US Department of Justice, the cost for accessing RSocks proxy pools ranged from $30 per day for 2,000 proxies to $200 per day for 90,000 proxies.
At that time, researchers identified 325,000 compromised devices, many of which were located in the United States. RSocks is reported to have compromised these devices by brute-forcing their access passwords and installing software on the compromised computers to turn them into proxy servers.

See also: Fronton botnet: It does much more than DDoS attacks
While the operation of RSocks has been shut down as a result of this international law‑enforcement operation, no arrests have been announced this time.
Botnet threat
Botnets are a constant, shape-shifting threat to unsecured devices, such as routers and other "smart" Internet of Things (IoT) connected to the Internet, which are often neglected and left to operate unattended for extended periods.
To protect IoT devices, owners should always change the default administrator password to something stronger that is difficult to crack, apply the latest available firmware , and create a separate network for IoT devices that is isolated from critical devices.
Information source: bleepingcomputer.com
