INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Law Enforcement Disrupts SocksEscort Proxy Network

| 2026-03-13 10:00 CRITICAL LOW
Executive Summary AI-generated
The SocksEscort proxy network, a malicious cyber operation, has been dismantled by international law enforcement partners. The US Department of Justice (DoJ) had previously stated that the application listed approximately 8000 infected routers in the country and offered access to its customers, who were also affected by the malware-infected routers enabling cybercriminals to conceal their true IP addresses and locations. Law enforcement agencies from Austria, France, and the Netherlands worked together to take down and seize domains and servers across seven countries. The operation was part of Operation Lightning, a global effort to dismantle malicious proxy services like SocksEscort.
Technical Mitigations AI-generated
* Regularly update router firmware to prevent exploitation of vulnerabilities and ensure the latest security patches are installed. * Use a reputable antivirus software and keep it up-to-date to detect and remove malware, including SocksEscort's botnet. * Implement a firewall on your network to block unauthorized access and limit potential damage from compromised devices. * Consider using a virtual private network (VPN) when accessing public Wi-Fi networks or connecting to unknown devices to encrypt internet traffic and protect against man-in-the-middle attacks.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation LightningOperation LightningOperation Winter ShieldOperation Winter Shield
Target & Sectors
BENELUX BENELUX NORTH_AMERICA NORTH_AMERICA DACH DACH governmentgovernment manufacturingmanufacturing
Incident Timeline
the summer of 2020
Threat actors used the SocksEscort proxy network to target law enforcement agencies in the United States.
source_region United States
organisation IP
organisation the US Justice Department
infrastructure 369,000 different IP addresses
2026-02-10
Threat actors used a proxy service to target 8,000 infected routers in the United States.
target_region United States
infrastructure 8000 infected routers
victims 2,500 customers
attribution FBI
campaign Operation Winter Shield
general_metric 10 key defensive measures
February 2026
Law enforcement agencies dismantled the SocksEscort proxy network.
target_region United States
organisation SocksEscort
organisation US Department of Justice
infrastructure 8000 infected routers
general_metric 2500 access
organisation IP
organisation Europol
organisation Virtual Command Post
organisation CSAM
organisation The European Union Agency
organisation Criminal Justice
organisation Eurojust
organisation Lumen Technologie’s Black Lotus Labs
organisation the Shadowserver Foundation
financial $6 Stolen / Extorted Funds
March 11
Law enforcement agencies seized 34 domains and 23 servers in seven countries.
infrastructure 34 domains
infrastructure 23 servers
2026-03-13
The FBI and law enforcement agencies seized 34 domains and 23 servers across seven countries as part of Operation Lightning, dismantling the SocksEscort proxy network blamed for compromising over 360,000 routers and IoT devices in163 countries since 2020.
financial $1 Stolen / Extorted Funds
organisation SocksEscort
financial $3.5 US
infrastructure 34 domains
infrastructure 23 servers
organisation IoT
infrastructure 360,000 routers
organisation the Shadowserver Foundation
organisation Black Lotus Labs
organisation AVRecon
organisation SOHO
victims 124,000 users
Tactical Metrics
Metrics
infrastructure
8,000
Infected Routers
Metrics
infrastructure
360,000
Routers
Metrics
infrastructure
34
Domains
Metrics
infrastructure
23
Servers
Metrics
financial
6,000,000
Stolen / Extorted Funds
Metrics
financial
3,500,000
Us
Metrics
infrastructure
369,000
Different Ip Addresses
Metrics
victims
2,500
Customers
Metrics
financial
1,000,000
Stolen / Extorted Funds
Metrics
victims
124,000
Users
Intelligence Sources
Infosecurity-Magazine 2026-03-13