Authorities Shut Down Proxy Service Linked to Malware Campaign Targeting Thousands of Users
An international law enforcement operation has dismantled SocksEscort, a significant malicious residential proxy network. The operation, led by the U.S. Justice Department and European partners, targeted an infrastructure that compromised numerous…
An international law enforcement operation has dismantled SocksEscort, a significant malicious residential proxy network. The operation, led by the U.S. Justice Department and European partners, targeted an infrastructure that compromised numerous residential and small business routers worldwide.
Authorities executed seizure warrants against multiple U.S.-registered domains, effectively halting a criminal service that facilitated substantial financial fraud. SocksEscort operated as an unauthorized residential proxy service powered by a large-scale botnet. The operators utilized malware to infect home and small office internet routers, allowing for unauthorized routing of third-party internet traffic.
The operators monetized this network by selling access to cybercriminals. Because the network traffic appeared to originate from legitimate residential internet service providers, it enabled attackers to bypass standard security filters and geolocation blocks.
The SocksEscort operation was extensive. Since mid-2020, the proxy service provided access to approximately 369,000 distinct IP addresses. Just before the takedown in February 2026, around 8,000 infected routers were listed for use, including 2,500 within the United States.
An international law enforcement operation has dismantled SocksEscort, a significant malicious residential proxy network.
Cybercriminals used this proxy access to conceal their IP addresses and locations, facilitating targeted attacks against U.S. individuals, businesses, and financial institutions. This anonymity contributed to significant financial cybercrime, including banking takeovers, cryptocurrency theft, and fraudulent unemployment insurance claims. Documented financial losses included:
A New York cryptocurrency exchange customer lost $1 million in digital assets. A Pennsylvania manufacturing business was defrauded of $700,000. $100,000 was stolen from MILITARY STAR card accounts of U.S. military personnel.
The dismantling required international cooperation. The FBI Sacramento Field Office, the IRS Criminal Investigation unit, and the Department of Defense led the American investigation. European agencies in Austria, France, and the Netherlands seized and dismantled key SocksEscort servers.
Europol, Eurojust, and authorities from Bulgaria, Germany, Hungary, and Romania supported the investigation. Private cybersecurity organizations, including Lumen’s Black Lotus Labs and the Shadowserver Foundation, provided critical threat intelligence. Through initiatives like the International Computer Hacking and Intellectual Property (ICHIP) network, global authorities continue to collaborate to combat cyber threats.
Based on reporting by GBHackers.
