#AVrecon
Law enforcement agencies in the U.S. and Europe along with private partners have disrupted the SocksEscort cybercrime proxy network that used only edge devices compromised via the AVRecon malware for Linux.
US disrupts SocksEscort proxy network powered by Linux malware
Law enforcement agencies in the U.S. and Europe along with private partners have disrupted the SocksEscort cybercrime proxy network that used only edge devices compromised via the AVRecon malware for Linux.
www.bleepingcomputer.com
March 12, 2026 at 4:20 PM
US disrupts SocksEscort proxy network powered by Linux malware
US disrupts SocksEscort proxy network powered by Linux malware
Law enforcement agencies in the U.S. and Europe along with private partners have disrupted the SocksEscort cybercrime proxy network that used only edge devices compromised via the AVRecon malware for Linux.
www.bleepingcomputer.com
March 12, 2026 at 4:34 PM
📢 AVrecon : le FBI démantèle SocksEscort et alerte sur un malware ciblant les routeurs SOHO
📝 ## 🌐 Contexte

Publié le 2 avril 2026 sur The Cyber Ex…
https://cyberveille.ch/posts/2026-04-02-avrecon-le-fbi-demantele-socksescort-et-alerte-sur-un-malware-ciblant-les-routeurs-soho/ #AVrecon #Cyberveille
April 2, 2026 at 11:30 PM
Beware of AVRecon botnet! It exploits compromised routers for illegal proxy services.
With 41,000 nodes in 20 countries, it's a major threat to online security.
Discover its connection to the 12-year-old SocksEscort service used by cybercriminals:
#hacking
AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service
Beware of AVRecon botnet! It exploits compromised routers for illegal proxy services.
thehackernews.com
July 31, 2023 at 9:00 PM
FBI Warns AVrecon Malware Compromised 369,000 Routers Worldwide in Proxy Network Scheme - HSToday www.hstoday.us/subject-matt...
FBI Warns AVrecon Malware Compromised 369,000 Routers Worldwide in Proxy Network Scheme - HSToday
The Federal Bureau of Investigation (FBI) has released a FLASH to disseminate indicators of compromise (IOCs) and identified tactics, techniques, and procedures (TTPs) associated with AVrecon malware
www.hstoday.us
March 17, 2026 at 7:45 AM
FBI Issues Critical Warning: AVrecon Malware Threatens Thousands of Routers and IoT Devices

In a recent FBI FLASH alert, cybersecurity authorities have revealed an alarming surge in AVrecon malware targeting routers and IoT devices worldwide. This malicious software, actively deployed by the…
FBI Issues Critical Warning: AVrecon Malware Threatens Thousands of Routers and IoT Devices
In a recent FBI FLASH alert, cybersecurity authorities have revealed an alarming surge in AVrecon malware targeting routers and IoT devices worldwide. This malicious software, actively deployed by the SocksEscort network, is compromising home and small-office devices, turning them into part of a massive residential proxy network. Experts are warning that unpatched or end-of-life devices are particularly vulnerable, raising urgent security concerns for both individuals and organizations.
undercodenews.com
April 1, 2026 at 4:14 AM
AVrecon, a stealthy SOHO router botnet, has silently grown for over 2 years! Over 70,000 routers infected, spanning 20 countries.
https://thehackernews.com/2023/07/new-soho-router-botnet-avrecon-spreads.html
#cybersecurity #informationsecurity #hacking
New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries
Alert! A new malware strain called AVrecon has quietly targeted over 70,000 small office/home office (SOHO) routers worldwide.
thehackernews.com
July 25, 2023 at 10:40 PM
The SocksEscort cybercrime proxy network has been dismantled in an international operation called Operation Lightning.
Authorities say compromised SOHO routers infected with the AVRecon botnet were used to route malicious traffic through residential IPs...
#Cybersecurity #Infosec #Botnet
March 13, 2026 at 10:10 AM
Global Law Enforcement Disrupts SocksEscort Proxy Network Powered by AVRecon Malware #Botnet #Botnetattack #CyberSecurity
Global Law Enforcement Disrupts SocksEscort Proxy Network Powered by AVRecon Malware
 Federal and regional police units, working alongside independent digital security experts, took down the SocksEscort hacking infrastructure. This setup used hacked gateway gadgets - infected by AVRecon - to route illicit online traffic through hidden channels.  A team at Black Lotus Labs, under Lumen Technologies, aided the takedown operation together with officials from the U.S. Department of Justice. Over multiple years, authorities found the proxy system kept around twenty thousand compromised gadgets active weekly - revealing both reach and staying power.  SocksEscort first came into view back in 2023, though signs point to activity stretching well beyond ten years. Operation relied on offering entry to seemingly legitimate IP addresses - pulled from home and office network devices. Because these connections appeared ordinary, users could mask malicious data flows under normal ISP cover. Detection tools often failed, misled by the everyday digital footprint left behind.  By early 2026, authorities reported the system had provided entry to vast numbers of IP addresses across its lifespan. Nearly 8,000 compromised routers remained operational at that point. Within the U.S., roughly a quarter of those devices were found scattered throughout the country. Though focused on one case, the ripple effects touched various forms of monetary misconduct.  A trail led authorities to connect SocksEscort with nearly $1 million siphoned from digital wallets belonging to someone in New York. Separate findings showed about $700,000 lost due to deceptive schemes targeting an industrial company based in Pennsylvania. Victims among American military personnel also faced damage after personal banking records were breached, adding further strain.  Dozens of domains and servers linked to the network were seized across Europe through joint efforts steered by Europol. Backing came from law enforcement agencies in Austria, France, and the Netherlands. Around $3.5 million in digital currency was blocked during the course of the mission. What powered the entire operation was AVRecon, a form of malicious software aimed at Linux-run home and small office routers.  By June 2023, it had taken hold on over seventy thousand machines, forming a vast network of hijacked devices. This network served one purpose: strengthening the reach of SocksEscort. Analysts found something unusual - none of the affected IPs showed up in unrelated botnet activity, pointing toward tightly managed usage. Despite setbacks during early 2023 that briefly disrupted operations through severed command channels, the group managed recovery by reconstructing systems. Control returned via decentralized nodes rather than a single hub. Activity restarted months afterward with modified communication pathways.  Early in 2025, more than 280,000 distinct IP addresses got caught up in the activity. Although infections spread globally, those based in the U.S. and the U.K. stood out - due to their appeal in hiding harmful network behavior. Outdated routers should be swapped out, many professionals suggest. Firmware updates come next on the list for staying protected. Default login details? Better revise them promptly. Remote functions that go unused tend to invite trouble - shutting those off helps block intrusions. Reducing exposure often begins with these small shifts.  A single operation reveals how digital crime groups using hidden relay systems are expanding their reach. Global teamwork across borders proves essential to weaken such operations.
dlvr.it
March 23, 2026 at 3:44 PM
On the latest episode of Safe Mode, @gregotto.bsky.social sits down with Chris Formosa to break down the Socksescort disruption—a proxy botnet powered by AVRecon that compromised edge devices at scale. www.youtube.com/watch?v=R0Jc... | www.youtube.com/watch?v=YxtB...
Chris Formosa breaks down the Socksescort disruption
YouTube video by CyberScoop
www.youtube.com
March 25, 2026 at 11:57 PM
SocksEscort: operação derruba rede usada por criminosos
Uma operação internacional de aplicação da lei derrubou o SocksEscort. Esse era um serviço criminoso que transformava roteadores domésticos em ferramentas de fraude sem que os donos soubessem. A ação foi liderada pelo Departamento de Justiça dos Estados Unidos e contou com a participação de autoridades de Áustria, Bulgária, França, Alemanha, Hungria, Holanda e Romênia. ## O que era o SocksEscort O SocksEscort infectava roteadores de casas e pequenas empresas com um malware chamado AVrecon. Depois de instalado, o programa permitia que o serviço redirecionasse o tráfego de internet pela conexão das vítimas. Essa capacidade era vendida a clientes pagantes. Desde o verão de 2020, o serviço comercializou acesso a cerca de 369 mil endereços IP diferentes, espalhados por 163 países. Em fevereiro de 2026, quando as investigações avançaram, o SocksEscort ainda listava cerca de 8 mil roteadores infectados disponíveis para compra. Desses, 2.500 estavam nos Estados Unidos. O serviço se anunciava abertamente. O site do SocksEscort prometia "IPs residenciais estáticos com banda ilimitada" e garantia que as conexões eram capazes de contornar listas de bloqueio de spam. Em dezembro de 2025, a plataforma dizia oferecer mais de 35.900 proxies de 102 países diferentes. Os preços eram acessíveis para o mundo do crime. Um pacote com 30 proxies custava US$ 15 por mês. Um pacote maior, com 5 mil proxies, saía por US$ 200 mensais. Para acessar o serviço, os clientes usavam uma plataforma de pagamento que permitia contratar tudo de forma anônima, usando criptomoedas. Estima-se que essa plataforma tenha recebido mais de 5 milhões de euros de clientes ao longo da operação. ## Como o golpe funcionava na prática Quando um criminoso comprava acesso ao SocksEscort, ele passava a navegar pela internet usando o endereço IP da vítima. Para sistemas de segurança e bancos, a conexão parecia vir de um usuário comum, e não de alguém cometendo fraude. O objetivo era fazer com que o tráfego malicioso se misturasse ao tráfego legítimo de milhões de usuários comuns. Essa técnica é chamada de proxy residencial. Ela serve para disfarçar a localização real de quem está aplicando o golpe, tornando muito mais difícil rastrear a origem do ataque. Com essa cobertura, os clientes do SocksEscort realizaram uma série de crimes. As fraudes incluíam invasões de contas bancárias e de criptomoedas, pedidos fraudulentos de seguro-desemprego. Entre os casos documentados, uma pessoa em Nova York teve US$ 1 milhão em criptomoedas roubados de sua conta em uma exchange. Uma empresa de manufatura na Pensilvânia perdeu US$ 700 mil. Militares e ex-militares americanos com cartões MILITARY STAR foram lesados em US$ 100 mil. O serviço não era direcionado a um único tipo de crime. Segundo a Europol, os dispositivos comprometidos foram usados para ataques de ransomware. Também fora registrados ataques de negação de serviço (DDoS) e distribuição de material de abuso sexual infantil. ## O malware por trás da operação O AVrecon é escrito na linguagem C e ataca principalmente dispositivos com processadores MIPS e ARM, arquiteturas comuns em roteadores domésticos. O FBI identificou que a maioria das infecções se aproveitava de falhas críticas nesses equipamentos, como execução remota de código. O malware mira aparelhos de marcas conhecidas. Cisco, D-Link, Hikvision, Mikrotik, Netgear, TP-Link e Zyxel estão entre os fabricantes cujos modelos foram explorados, em um total de cerca de 1.200 versões de dispositivos. Além de transformar o roteador infectado em um proxy residencial, o AVrecon era capaz de abrir um acesso remoto ao dispositivo e funcionar como um carregador de outros programas maliciosos, baixando e executando qualquer código que os criminosos desejassem. Para garantir que a infecção não fosse removida, os criminosos modificavam o próprio firmware do roteador. Além de inserir uma cópia do malware que iniciava automaticamente com o aparelho, a versão adulterada desabilitava os recursos de atualização e reinstalação do sistema original. O resultado era um dispositivo permanentemente comprometido. O AVrecon foi documentado publicamente pela empresa de segurança Lumen Black Lotus Labs em julho de 2023, mas as investigações indicam que o malware estava ativo pelo menos desde maio de 2021. Estima-se que, a partir do início de 2025, o serviço tenha vitimado 280 mil endereços IP distintos. Ao longo dos anos, o SocksEscort manteve uma média de 20 mil dispositivos infectados ativos por semana, com o tráfego sendo roteado por uma média de 15 servidores de comando e controle. ## O que a operação alcançou A ação, batizada de Operação Lightning, resultou na derrubada de 34 domínios e 23 servidores localizados em sete países. US$ 3,5 milhões em criptomoedas foram congelados. Autoridades da França, Áustria e Holanda foram responsáveis por derrubar os servidores. A Europol e a Eurojust coordenaram a cooperação entre os países. O Departamento de Justiça também executou mandados de apreensão contra dezenas de domínios de internet registrados nos Estados Unidos que estavam envolvidos na operação criminosa. A investigação contou com apoio do FBI, do Serviço de Investigação Criminal de Defesa, da Receita Federal americana e da empresa de segurança Lumen Black Lotus Labs, que havia documentado publicamente o AVrecon ainda em julho de 2023. Acompanhe o TecMundo nas redes sociais. Para mais notícias de segurança e tecnologia, inscreva-se em nossa newsletter e canal do YouTube.
www.tecmundo.com.br
March 13, 2026 at 11:24 PM
AryStinger is a new botnet that has hijacked 4,000+ outdated D-Link routers, turning them into proxies for scanning and malicious traffic, with infections concentrated in South Korea and China. #AryStinger #SouthKorea #DLink
AryStinger botnet infected thousands of D-Link routers worldwide
AryStinger is a previously undocumented botnet that has compromised more than 4,000 outdated routers, turning them into proxies for malicious traffic and distributed scanning. It targets older D-Link routers and some NAS systems, with infections concentrated in South Korea and China, while researchers have not yet linked it to a known threat actor. #AryStinger #DLinkDIR850L #DLinkDIR818LW #AVrecon #XLab
www.hendryadrian.com
June 21, 2026 at 5:45 PM
FBI alerts to AVrecon malware targeting 1,200+ router models worldwide by exploiting RCE, command injection, and SOAP flaws. Linked to SocksEscort proxy service used in banking and ad fraud across 163 countries. #AVrecon #SocksEscort #USA
FBI Warns of AVrecon Malware Targeting Network Devices Across 163 Countries
AVrecon is a modular router-targeting malware that scans for exposed services and exploits RCE, command injection, and SOAP flaws to convert home and SOHO routers into proxy nodes. Law enforcement linked AVrecon to the SocksEscort residential proxy service, which sold access to roughly 369,000 compromised devices used for banking fraud, ad...
www.hendryadrian.com
April 2, 2026 at 3:40 PM
US and European authorities disrupt socksEscort proxy service tied to AVrecon botnet
US and European authorities disrupt socksEscort proxy service tied to AVrecon botnet
Authorities in the US and Europe disrupted the SocksEscort proxy service, which used the AVrecon botnet and infected about 360,000 devices.
securityaffairs.com
March 13, 2026 at 4:06 PM
Experts link AVRecon bot to the malware proxy service SocksEscort - https://securityaffairs.com/149007/hacking/avrecon-bot-socksescort.html
Experts link AVRecon bot to the malware proxy service SocksEscort
<div style="margin-top:0px;margin-bottom:0px;"></div> <h2>The AVRecon botnet relies on compromised small office/home office (SOHO) routers since at least May 2021.</h2> <p>In early July, researchers from Lumen Black Lotus Labs discovered the <a href="https://securityaffairs.com/148447/cyber-crime/avrecon-botnet-targets-soho.html">AVRecon</a> botnet that targets small office/home office (SOHO) routers and infected over 70,000 devices from 20 countries. </p> <p>Threat actors behind the campaign aimed at building a botnet to use for a range of criminal activities from <a href="https://securityaffairs.com/124006/hacking/microsoft-warns-password-spraying-attacks.html">password spraying</a> to digital advertising fraud.</p> <p>The AVrecon malware was written in C to ensure portability and designed to target ARM-embedded devices. The experts discovered that the malicious code had been compiled for different architectures.</p> <p>On infected a router, the malware enumerates the victim’s SOHO router and sends that information back to a C2 server whose address is embedded in the code. Then, the infected system starts to begin interacting with a separate set of servers, the so-called second-stage C2 servers. </p> <p>Black Lotus Labs states AVrecon is one of the largest botnets targeting small-office/home-office (SOHO) -routers seen in recent history. The researchers identified 41,000 nodes communicating with second-stage C2s within a 28-day window.</p> <p><em>“Based on information associated with their x.509 certificates, we assess that some of these second stage C2s have been active since at least October 2021. We took a 28-day snapshot of the second stage servers and found more than 70,000 distinct IP addresses communicating with them.” continues the report. “We then investigated how many machines were persistently infected – meaning they communicated with one of the second stage servers for two or more days within the 28-day window – and we identified 41,000 nodes.”</em></p> <div> <a href="https://i0.wp.com/securityaffairs.com/wp-content/uploads/2023/07/image-22.png?ssl=1"><img width="404" height="276" src="https://i0.wp.com/securityaffairs.com/wp-content/uploads/2023/07/image-22.png?resize=404%2C276&amp;ssl=1" alt="AVrecon"></a></div> <p>Upon deploying the AVrecon RAT, the malware checks to see if other instances of the malware are already running on the system, it gathers host-based information, and builds the parameters of the C2 channel.</p> <p>The malware also checks if other instances of itself already running on the host by searching for existing processes on port 48102 and opening a listener on that port.</p> <p>Most of the infected routers are in the U.K. and the U.S., followed by Argentina, Nigeria, Brazil, Italy, Bangladesh, Vietnam, India, Russia, and South Africa, among others.</p> <p>The threat actors were observed using the infected machines to click on various Facebook and Google ads, and to interact with Microsoft Outlook. The first activity is part of an advertising fraud effort, and the second activity is likely linked to password spraying attacks and/or data exfiltration. </p> <p>The popular investigator Brian Krebs and <a href="https://www.spur.us/">Spur.us</a> investigated the botnet and discovered that the bot is the malware engine behind a 12-year-old service called SocksEscort. Operators behind SocksEscort offer for rent access to compromised residential and small business devices.</p> <p><em>“<strong>SocksEscort[.]com</strong>, is what’s known as a “SOCKS Proxy” service. The SOCKS (or SOCKS5) protocol allows Internet users to channel their Web traffic through a proxy server, which then passes the information on to the intended destination. From a website’s perspective, the traffic of the proxy network customer appears to originate from a rented/malware-infected PC tied to a residential ISP customer, not from the proxy service customer.” reads the <a href="https://krebsonsecurity.com/2023/07/who-and-what-is-behind-the-malware-proxy-service-socksescort/">post</a> published by KrebsOnSecurity. “Spur tracks SocksEscort as a malware-based proxy offering, which means the machines doing the proxying of traffic for SocksEscort customers have been infected with malicious software that turns them into a traffic relay. Usually, these users have no idea their systems are compromised.”</em></p> <p>Customers of the SocksEscort proxy service have to install a Windows-based application to access a pool of more than 10,000 hacked devices worldwide.</p> <p><a href="https://www.spur.us/">Spur</a> researchers created a fingerprint to identify the call-back infrastructure for SocksEscort proxies, they were able to determine that operators use AVrecon to server proxies to the SocksEscort service.</p> <p><em>“When Lumen released their report and IOCs [indicators of compromise], we queried our system for which proxy service call-back infrastructure overlapped with their IOCs,” said Spur co-founder Riley Kilmer. “The second stage C2s they identified were the same as the IPs we labeled for SocksEscort.”</em></p> <p>KrebsOnSecurity <a href="https://krebsonsecurity.com/2023/07/who-and-what-is-behind-the-malware-proxy-service-socksescort/">linked</a> the malware proxy network to a Moldovan company named Server Management LLC that also offers VPN software on the Apple Store and elsewhere. </p> <p>Follow me on Twitter: <a href="https://twitter.com/securityaffairs"><strong>@securityaffairs</strong></a> <a href="https://www.facebook.com/sec.affairs"><strong>Facebook</strong></a> and <a href="https://infosec.exchange/@securityaffairs"><strong>Mastodon</strong></a></p> <p><a href="http://www.linkedin.com/pub/pierluigi-paganini/b/742/559"><strong>Pierluigi Paganini</strong></a></p> <p><strong>(</strong><a href="http://securityaffairs.co/wordpress/"><strong>SecurityAffairs</strong></a><strong> –</strong> <strong>hacking,</strong> <strong>AVRecon)</strong></p> <p></p> <p>The post <a href="https://securityaffairs.com/149007/hacking/avrecon-bot-socksescort.html">Experts link AVRecon bot to the malware proxy service SocksEscort</a> appeared first on <a href="https://securityaffairs.com">Security Affairs</a>.</p>
securityaffairs.com
July 31, 2023 at 12:27 PM
Who and What is Behind the Malware Proxy Service SocksEscort?
<p>Researchers this month uncovered a two-year-old Linux-based remote access trojan dubbed <strong>AVrecon</strong> that enslaves Internet routers into botnet that bilks online advertisers and performs password-spraying attacks. Now new findings reveal that AVrecon is the malware engine behind a 12-year-old service called <strong>SocksEscort</strong>, which rents hacked residential and small business devices to cybercriminals looking to hide their true location online.</p> <div style="width:673px;"><img src="https://krebsonsecurity.com/wp-content/uploads/2023/07/avrecon.png" alt="" width="663" height="509"><p>Image: Lumen’s Black Lotus Labs.</p></div> <p>In a report released July 12, researchers at Lumen’s <strong>Black Lotus Labs</strong> called the AVrecon botnet “one of the largest botnets targeting small-office/home-office (SOHO) routers seen in recent history,” and a crime machine that has largely evaded public attention since first being spotted in mid-2021.</p> <p>“The malware has been used to create residential proxy services to shroud malicious activity such as <a href="https://www.crowdstrike.com/cybersecurity-101/password-spraying/">password spraying</a>, web-traffic proxying and ad fraud,” the Lumen researchers <a href="https://blog.lumen.com/routers-from-the-underground-exposing-avrecon/">wrote</a>.</p> <p>Malware-based anonymity networks are a major source of unwanted and malicious web traffic directed at online retailers, Internet service providers (ISPs), social networks, email providers and financial institutions. And a great many of these “proxy” networks are marketed primarily to cybercriminals seeking to anonymize their traffic by routing it through an infected PC, router or mobile device.</p> <p>Proxy services can be used in a legitimate manner for several business purposes — such as price comparisons or sales intelligence — but they are massively abused for hiding cybercrime activity because they make it difficult to trace malicious traffic to its original source. Proxy services also let users appear to be getting online from nearly anywhere in the world, which is useful if you’re a cybercriminal who is trying to impersonate someone from a specific place.</p> <p><a href="https://www.spur.us/">Spur.us</a>, a startup that tracks proxy services, told KrebsOnSecurity that the Internet addresses Lumen tagged as the AVrecon botnet’s “Command and Control” (C2) servers all tie back to a long-running proxy service called <strong>SocksEscort</strong>.</p> <p><strong>SocksEscort[.]com</strong>, is what’s known as a “SOCKS Proxy” service. The SOCKS (or SOCKS5) protocol allows Internet users to channel their Web traffic through a proxy server, which then passes the information on to the intended destination. From a website’s perspective, the traffic of the proxy network customer appears to originate from a rented/malware-infected PC tied to a residential ISP customer, not from the proxy service customer.</p> <div style="width:760px;"><img src="https://krebsonsecurity.com/wp-content/uploads/2022/08/socksescort-home.png" alt="" width="750" height="677"><p>The SocksEscort home page says its services are perfect for people involved in automated online activity that often results in IP addresses getting blocked or banned, such as Craigslist and dating scams, search engine results manipulation, and online surveys.</p></div> <p>Spur tracks SocksEscort as a malware-based proxy offering, which means the machines doing the proxying of traffic for SocksEscort customers have been infected with malicious software that turns them into a traffic relay. Usually, these users have no idea their systems are compromised.</p> <p>Spur says the SocksEscort proxy service requires customers to install a Windows based application in order to access a pool of more than 10,000 hacked devices worldwide.</p> <p>“We created a fingerprint to identify the call-back infrastructure for SocksEscort proxies,” Spur co-founder <strong>Riley Kilmer</strong> said. “Looking at network telemetry, we were able to confirm that we saw victims talking back to it on various ports.”</p> <p>According to Kilmer, AVrecon is the malware that gives SocksEscort its proxies.</p> <p>“When Lumen released their report and IOCs [indicators of compromise], we queried our system for which proxy service call-back infrastructure overlapped with their IOCs,” Kilmer continued. “The second stage C2s they identified were the same as the IPs we labeled for SocksEscort.”</p> <p>Lumen’s research team said the purpose of AVrecon appears to be stealing bandwidth – without impacting end-users – in order to create a residential proxy service to help launder malicious activity and avoid attracting the same level of attention from <a href="https://community.torproject.org/onion-services/setup/">Tor-hidden services</a> or commercially available VPN services.</p> <p>“This class of cybercrime activity threat may evade detection because it is less likely than a crypto-miner to be noticed by the owner, and it is unlikely to warrant the volume of abuse complaints that internet-wide brute-forcing and DDoS-based botnets typically draw,” Lumen’s Black Lotus researchers wrote.</p> <p>Preserving bandwidth for both customers and victims was a primary concern for SocksEscort in July 2022, when 911S5 — at the time the world’s largest known malware proxy network — <a href="https://krebsonsecurity.com/2022/07/911-proxy-service-implodes-after-disclosing-breach/">got hacked and imploded</a> just days after <a href="https://krebsonsecurity.com/2022/07/a-deep-dive-into-the-residential-proxy-service-911/">being exposed in a story here</a>. Kilmer said after 911’s demise, SocksEscort closed its registration for several months to prevent an influx of new users from swamping the service.</p> <p><strong>Danny Adamitis</strong>, principal information security researcher at Lumen and co-author of the report on AVrecon, confirmed Kilmer’s findings, saying the C2 data matched up with what Spur was seeing for SocksEscort dating back to September 2022.</p> <p>Adamitis said that on July 13 — the day after Lumen published research on AVrecon and started blocking any traffic to the malware’s control servers — the people responsible for maintaining the botnet reacted quickly to transition infected systems over to a new command and control infrastructure.</p> <p>“They were clearly reacting and trying to maintain control over components of the botnet,” Adamitis said. “Probably, they wanted to keep that revenue stream going.”</p> <p>Frustratingly, Lumen was not able to determine how the SOHO devices were being infected with AVrecon. Some possible avenues of infection include exploiting weak or default administrative credentials on routers, and outdated, insecure firmware that has known, exploitable security vulnerabilities.<br> <span></span></p> <h2>WHO’S BEHIND SOCKSESCORT?</h2> <p>KrebsOnSecurity <a href="https://krebsonsecurity.com/2022/08/no-socks-no-shoes-no-malware-proxy-services/">briefly visited SocksEscort last year</a> and promised a follow-up on the history and possible identity of its proprietors. A review of the earliest posts about this service on Russian cybercrime forums suggests the 12-year-old malware proxy network is tied to a Moldovan company that also offers VPN software on the Apple Store and elsewhere.</p> <p>SocksEscort began in 2009 as “<a href="https://web.archive.org/web/20130406151624/http://super-socks.biz/"><strong>super-socks[.]com</strong></a>,” a Russian-language service that sold access to thousands of compromised PCs that could be used to proxy traffic. Someone who picked the nicknames “<strong>SSC</strong>” and “<strong>super-socks</strong>” and email address “<strong>michvatt@gmail.com</strong>” registered on multiple cybercrime forums and began promoting the proxy service.</p> <p>According to <a href="https://www.domaintools.com">DomainTools.com</a>, the apparently related email address “<strong>michdomain@gmail.com</strong>” was used to register SocksEscort[.]com, super-socks[.]com, and a few other proxy-related domains, including <strong>ip-score[.]com</strong>, segate[.]org seproxysoft[.]com, and <strong>vipssc[.]us</strong>. Cached versions of both super-socks[.]com and <a href="https://web.archive.org/web/20111028204532/http://www.vipssc.us/">vipssc[.]us</a> show these sites sold the same proxy service, and both displayed the letters “<strong>SSC</strong>” prominently at the top of their homepages.</p> <div style="width:760px;"><img src="https://krebsonsecurity.com/wp-content/uploads/2022/08/ssc-proxy.png" alt="" width="750" height="593"><p>Image: Archive.org. Page translation from Russian via Google Translate.</p></div> <p>According to cyber intelligence firm <a href="https://www.intel471.com">Intel 471</a>, the very first “SSC” identity registered on the cybercrime forums happened in 2009 at the Russian language hacker community <strong>Antichat</strong>, where SSC registered using the email address <strong>adriman@gmail.com</strong>. SSC asked fellow forum members for help in testing the security of a website they claimed was theirs: <a href="https://web.archive.org/web/20090109091552/http://myiptest.com/">myiptest[.]com</a>, which promised to tell visitors whether their proxy address was included on any security or anti-spam block lists.</p> <p>DomainTools says myiptest[.]com was registered in 2008 to an <strong>Adrian Crismaru</strong> from Chisinau, Moldova. Myiptest[.]com is no longer responding, but a cached copy of it from <a href="https://web.archive.org/web/20100102003637/http://myiptest.com/">Archive.org</a> shows that for about four years it included in its HTML source a Google Analytics code of <strong>US-2665744</strong>, which was also present on more than a dozen other websites.</p> <p>Most of the sites that once bore that Google tracking code are no longer online, but nearly all of them centered around services that were similar to myiptest[.]com, such as <strong>abuseipdb[.]com</strong>, <strong>bestiptest[.]com</strong>, <strong>checkdnslbl[.]com</strong>,<strong> dnsbltools[.]com</strong> and <strong>dnsblmonitor[.]com</strong>.</p> <p>Each of these services were designed to help visitors quickly determine whether the Internet address they were visiting the site <em>from</em> was listed by any security firms as spammy, malicious or phishous. In other words, these services were designed so that proxy service users could easily tell if their rented Internet address was still safe to use for online fraud.</p> <p>Another domain with the Google Analytics code US-2665744 was<strong> sscompany[.]net</strong>. <a href="https://web.archive.org/web/20090205172352/http://sscompany.net:80/">An archived copy of the site</a> says SSC stands for “<strong>Server Support Company</strong>,” which advertised outsourced solutions for technical support and server administration. The company was located in Chisinau, Moldova and owned by Adrian Crismaru.</p> <p>Leaked copies of the hacked Antichat forum indicate the SSC identity tied to adriman@gmail.com registered on the forum using the IP address <strong>71.229.207.214</strong>. That same IP was used to register the nickname “<strong>Deem3n®,</strong>” a prolific poster on Antichat between 2005 and 2009 who served as a moderator on the forum.</p> <p>There was a <strong>Deem3n® </strong>user on the webmaster forum Searchengines.guru whose signature in their posts says they run a popular community catering to programmers in Moldova called <strong>sysadmin[.]md</strong>, and that they were a systems administrator for sscompany[.]net.</p> <p>That same Google Analytics code is also now present on the homepages of <strong>wiremo[.]co</strong> and a VPN provider called <strong>HideIPVPN[.]com</strong>.</p> <p><a href="https://web.archive.org/web/20230209032519/https://wiremo.co/">Wiremo</a> sells software and services to help website owners better manage their customer reviews. Wiremo’s Contact Us page lists a “<strong>Server Management LLC</strong>” in Wilmington, DE as the parent company. Records from the Delaware Secretary of State indicate Crismaru is CEO of this company.</p> <p>Server Management LLC is <a href="https://apps.apple.com/ru/app/hideipvpn-vpn-smart-dns/id964479810">currently listed</a> in Apple’s App Store as the owner of a “free” VPN app called <strong>HideIPVPN</strong>. The contact information on <a href="https://www.linkedin.com/in/adriancrismaru/">Crismaru’s LinkedIn page</a> says his company websites include myiptest[.]com, sscompany[.]net, and hideipvpn[.]com.</p> <p>“The best way to secure the transmissions of your mobile device is VPN,” reads HideIPVPN’s description on the Apple Store. “Now, we provide you with an even easier way to connect to our VPN servers. We will hide your IP address, encrypt all your traffic, secure all your sensitive information (passwords, mail credit card details, etc.) form [sic] hackers on public networks.”</p> <p>Mr. Crismaru did not respond to multiple requests for comment. When asked about the company’s apparent connection to SocksEscort, Wiremo responded, “We do not control this domain and no one from our team is connected to this domain.” Wiremo did not respond when presented with the findings in this report.</p>
krebsonsecurity.com
July 25, 2023 at 9:31 PM
⚠️Η διεθνής επιχείρηση κατά της υπηρεσίας proxy SocksEscort και του malware AVrecon. Δείτε πώς παραβιάστηκαν routers των TP-Link, Netgear και D-Link. #SocksEscort #AVrecon #Netgear #TPLink #DLink #CyberSecurityNews
SocksEscort: FBI και Europol «γκρέμισαν» το δίκτυο που μόλυνε 369.000 routers και συσκευές IoT
Με τη χρήση του κακόβουλου λογισμικού AVrecon, οι χάκερ εκμεταλλεύονταν δρομολογητές γνωστών εταιρειών για να κρύβουν εγκληματικές δραστηριότητες εκατομμυρίων ευρώ.
gr.pcmag.com
March 22, 2026 at 3:50 PM
📢 Symbiose entre services de proxies résidentiels et écosystèmes malware : analyse sur 55 jours
📝 ## 🔍 Contexte

Publié le 7 mai 2026 par Valter…
https://cyberveille.ch/posts/2026-05-08-symbiose-entre-services-de-proxies-residentiels-et-ecosystemes-malware-analyse-sur-55-jours/ #AVRecon #Cyberveille
May 8, 2026 at 11:30 AM