Authorities in multiple countries have dismantled a large cybercrime platform known as SocksEscort that covertly hijacked hundreds of thousands of internet-connected devices and sold access to them as residential proxies used to conceal criminal activity online.

Authorities in multiple countries have dismantled a large cybercrime platform known as SocksEscort that covertly hijacked hundreds of thousands of internet-connected devices and sold access to them as residential proxies used to conceal criminal activity online.
The operation targeted SocksEscort, a proxy service that enabled customers to route internet traffic through compromised home and small-business routers, allowing cybercriminals to hide their real locations and IP addresses while conducting fraud and other illegal activities. The service is believed to have compromised and sold access to roughly 369,000 devices in 163 countries since the summer of 2020.
The U.S. Department of Justice announced that the takedown resulted from a coordinated international effort involving law enforcement agencies from Austria, Bulgaria, France, Germany, Hungary, the Netherlands, Romania, and the United States. Investigators seized 34 domains and 23 servers located across seven countries and froze approximately $3.5 million in cryptocurrency linked to the operation.
Europol confirmed that the infected modems used to provide the proxy service have been disconnected from the platform, effectively dismantling the infrastructure that enabled the criminal network.
SocksEscort marketed itself as a residential proxy network that provided “static residential IPs with unlimited bandwidth.” Customers could purchase subscription plans starting at $15 per month for access to 30 residential IP connections, while larger packages offering 5,000 proxies were priced at about $200 per month. Payments were processed through cryptocurrency-based systems designed to maintain user anonymity.
The service functioned by infecting internet routers with malware that redirected traffic through the compromised devices without the owners’ knowledge. By tunneling traffic through ordinary household connections, cybercriminals could blend malicious activity with legitimate internet usage, making detection more difficult.
The infrastructure relied on malware known as AVrecon, which targeted roughly 1,200 device models manufactured by networking vendors including Cisco, D-Link, Hikvision, Mikrotik, Netgear, TP-Link, and Zyxel. The malware primarily affected small office and home office routers by exploiting security vulnerabilities such as remote code execution and command injection flaws.
Once installed, AVrecon could establish a remote shell connection to attacker-controlled servers and download additional malicious payloads. The malware also modified device firmware to ensure it executed automatically whenever the device restarted, while disabling normal update mechanisms to keep the infection persistent.
Investigators estimate the platform generated more than €5 million, or about $5.7 million, in revenue from customers who purchased proxy access.
Authorities said the compromised routers were used to support a wide range of cybercrime operations. These included account takeover attacks targeting U.S. bank and cryptocurrency accounts, fraudulent unemployment insurance claims, distributed denial-of-service attacks, ransomware activity, and the distribution of child sexual abuse material.
Several major fraud cases have already been linked to the network. One victim in New York lost approximately $1 million in cryptocurrency, while a manufacturing company in Pennsylvania was defrauded of $700,000. Current and former U.S. service members using MILITARY STAR credit accounts also lost about $100,000 in related schemes.
Before the law enforcement operation disrupted the platform, the network offered access to around 8,000 actively infected routers at a given time, including approximately 2,500 devices located in the United States.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543