US and Europol Dismantle SocksEscort Botnet Powered by AVRecon Linux Malware
Mar 12, 2026 // 20:57 - Niko Dunn


The U.S. Department of Justice, in coordination with international partners, has disrupted the SocksEscort proxy network, which utilized a massive botnet of infected Linux devices to facilitate cybercrime.

Key Facts of the Takedown

  • The Network: SocksEscort operated as a “proxy-as-a-service” platform, allowing paying customers to route malicious traffic through a network of over 1 million hijacked devices (primarily servers and IoT devices) globally.
  • The Malware: The botnet was powered by a sophisticated Linux-based malware dubbed SocksEscort, which turned compromised systems into SOCKS5 proxy nodes without the owners’ knowledge.
  • Impacted Systems: While the network spanned 150 countries, a significant portion of the “residential” proxies were located in the United States.
  • The Disruption: Authorities seized the command-and-control (C2) infrastructure and domain names used to manage the botnet, effectively severing the connection between the botmasters and the infected hosts.

Usage in Cybercrime

The network was a favorite for threat actors involved in:

  • Credential Stuffing: Masking automated login attempts to bypass geographic blocks.
  • Phishing Campaigns: Routing emails through legitimate IP addresses to avoid spam filters.
  • Financial Fraud: Conducting unauthorized transactions using residential IPs to appear as legitimate local users.

This operation follows similar recent takedowns, such as the 911 S5 and IPStorm botnets, as law enforcement continues to target the infrastructure that enables large-scale anonymity for criminals.

#and  #avrecon  #botnet  #dismantle  #europol  #linux  #malware  #news  #powered  #socksescort   —   News