US, Europol disrupt SocksEscort network that exploited thousands of residential routers
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是美国和欧洲执法机构打击了一个网络犯罪平台SocksEscort。这个平台允许网络罪犯购买被恶意软件感染的路由器的访问权限,从而隐藏他们的位置和IP地址。从2020到2026年,该平台提供了约36.9万个IP地址,涉及163个国家。执法行动中没收了34个域名,关闭了23个服务器,并冻结了价值350万美元的加密货币。 此外,FBI还警告了一种名为AVRecon的恶意软件,专门针对路由器和物联网设备。SocksEscort利用这种恶意软件攻击多个品牌的路由器型号。欧洲刑警组织指出,被感染设备的主人通常不知道自己的IP地址被滥用。 整个行动涉及多个国家的执法机构,并得到了私营部门的支持。SocksEscort背后的人员据称赚取了超过570万美元。这个平台被用于多种网络犯罪活动,包括欺诈性失业保险索赔、加密货币盗窃和银行账户接管。 总结时需要包括:执法机构的行动、平台的功能、涉及的数量、执法措施以及相关恶意软件的信息。控制在100字以内,直接描述内容。 </think> 美国和欧洲执法机构捣毁了一个名为SocksEscort的网络犯罪平台,该平台允许网络罪犯通过被感染的路由器隐藏身份并进行非法活动。从2020年到2026年,该平台提供了约36.9万个IP地址,并涉及163个国家。执法行动中没收了34个域名和23个服务器,并冻结了价值350万美元的加密货币。该平台还与名为AVRecon的恶意软件相关联,专门针对路由器和物联网设备。 2026-3-12 21:30:49 Author: therecord.media(查看原文) 阅读量:4 收藏

A cybercriminal platform that offered access to thousands of residential routers was disrupted by law enforcement agencies in the U.S. and Europe on Wednesday. 

The SocksEscort proxy network allowed cybercriminals to purchase access to routers infected with malware. Criminals could conceal their location and IP address by routing their activities through the infected routers. 

The Justice Department said from 2020 to 2026, SocksEscort offered access to about 369,000 different IP addresses in 163 countries but listed about 8,000 IP addresses as of February. Of those 8,000 available for sale, 2,500 were in the U.S. 

In total, 34 domains were seized and 23 servers were taken down by law enforcement agencies in seven countries. U.S. officials also froze access to $3.5 million worth of cryptocurrency. 

Alongside the operation against SocksEscort, the FBI published a flash alert about a malware strain known as AVRecon on Thursday, warning the public that it is targeted at routers and internet-of-things devices.

Threat actors “have been found to compromise routers, install AVrecon Malware, and then sell access to the compromised devices as residential proxies using the SocksEscort residential proxy service.”

SocksEscort uses AVrecon malware “to target approximately 1,200 device models manufactured by Cisco, D-Link, Hikvision, MicroTik, Netgear, TP-Link, and Zyxel,” the FBI said. Europol noted that when the devices were infected with the malware, owners would not know that their IP address was being abused.  

Catherine De Bolle, executive director of Europol, said proxy services like SocksEscort “provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection.” 

“By dismantling this infrastructure, law enforcement has disrupted a service that enabled cybercrime on a global scale,” De Bolle said in a statement. 

U.S. officials executed seizure warrants against several U.S. domains that enabled the SocksEscort operation. 

Court documents tied the SocksEscort site to dozens of different cyberscams, including fraudulent unemployment insurance claims, cryptocurrency thefts and the takeover of U.S. bank accounts. 

The people behind SocksEscort allegedly netted more than $5.7 million from the service. 

Law enforcement agencies in Austria, France and the Netherlands took down SocksEscort servers and officials in Bulgaria, Germany, Hungary and Romania were involved in the investigation, which began in June 2025. The DOJ noted that private sector firms like Lumen’s Black Lotus Labs and the Shadowserver Foundation also provided assistance. 

Black Lotus Labs published its own advisory on AVRecon and SocksEscort, writing that over the past several years, the platform “maintained an average size of approximately 20,000 distinct victims weekly, with communications routed through an average of 15 command-and-control nodes (C2s).” 

In 2023, the company said AVrecon’s botnet was one of the largest it has seen targeting home office routers. 

An FBI official told The Register that SocksEscort had 124,000 users and that they planned to use the seized servers to target other cybercriminal activity. 

U.S. and European law enforcement agencies have ramped upbotnet takedowns in recent years to stymie cybercriminal and nation-state attack campaigns. Botnets like QakBot, 911 S5, IPStorm, KV, DanaBot, Anyproxy, 5socks and others have faced law enforcement scrutiny since 2021.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/us-europol-disrupt-socksescort-network
如有侵权请联系:admin#unsafe.sh