A global coalition of law enforcement agencies on Wednesday dismantled a botnet consisting of tens of thousands of hacked routers (primarily used in homes and small businesses). Specifically, the operation targeted SocksEscort , which offered paid proxy services and was built on top of a botnet of hacked routers used to carry out various crimes, including hacking into victims’ bank and cryptocurrency accounts , as well as submitting false claims for unemployment benefits , according to a statement released by the U.S. Department of Justice.

The Department of Justice reported that crimes facilitated by SocksEscort cost Americans millions of dollars.
See also: Aisuru botnet: New record with 31.4 Tbps DDoS attack
Europol said in its statement about the operation that the SocksEscort botnet allegedly compromised more than 369,000 routers and Internet of Things devices in 163 countries and that the infected routers “have been disconnected from service.” The law enforcement agency noted that SocksEscort was used to facilitate ransomware attacks, DDoS attacks , and the distribution of child sexual abuse material (CSAM).
“The criminal agency’s clients paid for licenses to use these infected devices, hiding their original IP addresses to engage in various criminal activities,” Europol said. “After infection with the malware, the modem owners would not be aware that their IP addresses were being used for illegal activities.”
See also: RondoDox Botnet exploits vulnerability in HPE OneView
The content of SocksEscort's official website was replaced by a notice announcing the seizure, as part of the law enforcement operation.

SocksEscort botnet: Thousands of routers affected
According to cybersecurity firm Black Lotus Labs, the botnet consisted of around 280,000 routers as of last January and was powered by malware called AVRecon.
“This botnet posed a significant threat, as it was exclusively marketed to criminals,” the company wrote in its takedown post. “Over half of its victims were located in the United States or the United Kingdom, allowing attackers to conduct highly targeted operations.”
See also: SSHStalker botnet compromises Linux machines via brute-force

In 2023, Black Lotus Labs called SocksEscort “one of the largest botnets in recent history, targeting small office/home (SOHO) routers.”
At the time, cybersecurity journalist Brian Krebs reported that SocksEscort was born in 2009 as a Russian-language service that sold access to thousands of hacked computers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
