The router in your home office or small business doesn’t need to be compromised by a skilled operator to end up serving as a platform for banking or other fraud. All it takes is an unpatched vulnerability and a malware called “AVrecon” to infect the device and sell access to it within minutes.

Last month, the FBI, along with several international law enforcement agencies, took down SocksEscort, a residential proxy service. As part of that investigation, the agency discovered the AVrecon malware, which was used to target multiple network devices worldwide.
How the new AVrecon threat works
AVrecon spreads by scanning the internet for devices with exposed vulnerable services. SocksEscort operators exploited remote code execution and command injection vulnerabilities, as well as weaknesses in exposed SOAP interfaces — a web services protocol found in many consumer router control panels.
The malware's command-and-control framework is designed in a modular manner, meaning new exploit modulesas new vulnerabilities are discovered. The FBI identified approximately 1,200 targeted device models from Cisco, D-Link, Hikvision, MikroTik, Netgear, TP-Link, and Zyxel.
See also: CrystalRAT: New MaaS service advertised via Telegram
In addition to turning infected devices into proxy nodes, AVrecon can also update its own stored configuration, create a remote shell directly to a server controlled by the attacker, and act as a loader that downloads and executes completely separate payloads on the device.
Once inside a router, the malware communicates with its command and control server every 60 seconds using a PING/PONG communication loop. When the C2 has a command ready, it interrupts this loop to direct the infected router to open a traffic tunnel to a SocksEscort relay server.

Persistence Mechanism
The persistence mechanism used by AVrecon on certain device models makes recovery particularly difficult. On vulnerable targets, attackers use the device's built-in firmware update feature to create a custom firmware image that contains a hardcoded copy of AVrecon and silently disables future update and re-flashing functionality on the device.
The FBI notes that these devices are essentially permanently infected — a factory reset cannot help if the reset itself has been disabled, and a device that has reached “end of life” does not receive patches from the manufacturer to address the underlying vulnerability.
See also: WhatsApp: Italian spyware company created fake iOS version
On devices where no firmware modification is used, a simple power cycle can clear the infection. However, in at least one case, AVrecon's C2 servers detected the loss of an infected device and automatically reinfected it using the same vulnerabilities used in the original breach. This means that a reboot alone does not guarantee lasting protection if the underlying vulnerability remains unpatched.
SocksEscort Service
SocksEscort was selling customers the ability to route internet traffic through compromised home and small office routers in 163 countries, including the United States. The tunneling protocol used — SOCKS — is a legitimate networking standard that routes traffic through an intermediate host. However, it also makes the attacker’s activity appear to originate from the victim’s IP address rather than from any infrastructure that could be blocked or traced.
The FBI estimates that SocksEscort compromised and sold access to about 369,000 devices as of 2020. The malware that enabled all of this was AVrecon — written in the C programming language and designed to target devices running on MIPS and ARM architectures, the types of processors that dominate the consumer router.
The FBI and its partners observed that SocksEscort’s infrastructure was used to execute ad fraud, website exploits , password spraying attacks, digital shopping fraud, banking fraud, and romance scams, among other malicious activities. By routing attacks through residential IP addresses, SocksEscort’s customers dramatically increased their chances of bypassing corporate security filters and blacklists that flag traffic from known commercial or cloud hosting providers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: “WhatsApp malware” campaign uses malicious VBS files

What network defenders should do
The FBI recommends applying firmware updates to all SOHO routers and IoT devices, as many do not apply patches automatically and require manual interaction with the device's management panel. Devices classified as End-of-Life and no longer receiving security updates should be completely replaced.
Remote management features should be disabled or restricted , and all default passwords should be changed.
Network defenders should monitor traffic to the C2 domains and IP addresses published in the advisory and monitor the malware filenames “x” (loader) and “dnssmasq” (malware) on devices connected to the network.
