Back to News
technology

Law enforcement shuts down botnet made of tens of thousands of hacked routers

Lorenzo Franceschi-Bicchierai
Loading...
3 min read
0 likes
⚡ Quantum Brief
A global law enforcement operation dismantled a massive botnet comprising tens of thousands of hacked routers, disrupting cybercriminal activities worldwide. The takedown targeted SocksEscort, a proxy service enabling ransomware, DDoS attacks, and child abuse material distribution. SocksEscort’s infrastructure relied on 369,000 compromised routers and IoT devices across 163 countries, per Europol. The botnet, active since 2009, masked criminals’ IP addresses, facilitating fraud, bank hacks, and unemployment scams costing millions. The botnet used AVRecon malware, infecting 280,000 routers by January 2026, per Black Lotus Labs. Over half the victims were in the U.S. and U.K., enabling highly targeted cyberattacks. Authorities seized SocksEscort’s website, replacing it with a law enforcement notice. The service sold licenses to criminals, exploiting unaware router owners for illegal activities. Cybersecurity firm Black Lotus Labs, which tracked SocksEscort since 2023, assisted in the takedown, calling it one of the largest SOHO router botnets in recent history.
AI Audio Summary
0:00 / 0:00
Click to play
ilya-pavlov-OqtafYT5kTw-unsplash.jpg
Quantum News · Media Library

Founder Summit 2026 in Boston: Don’t miss ticket savings of up to $300. Register Now.Save up to $680 on your Disrupt 2026 pass. Ends 11:59 p.m. PT tonight. REGISTER NOW. Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture Staff Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us A global coalition of law enforcement agencies shut down a botnet made of tens of thousands of hacked home and small business routers on Wednesday.The operation targeted SocksEscort, which offered paid proxy services and was built on a botnet of hacked routers used to commit various crimes, such as hacking into victims’ bank and cryptocurrency accounts and filing fraudulent unemployment insurance claims, according to an announcement published on Thursday by the Department of Justice (DOJ). The DOJ said the crimes facilitated by SocksEscort cost Americans millions of dollars. Europol said in its announcement of the operation that the SocksEscort botnet allegedly compromised more than 369,000 routers and Internet of Things devices in 163 countries and that the infected routers “have been disconnected from the service.” The law enforcement agency said SocksEscort was used to facilitate ransomware, distributed denial of service (DDoS) attacks, and the distribution of child sexual abuse material (CSAM).“Customers of the criminal service paid for licenses to abuse these infected devices, hiding their original IP addresses to engage in various criminal activities,” said Europol. “Upon infection with the malware, the modems’ owners would not be aware that their IP addresses were used for illegitimate activities.”The content of the SocksEscort official website was replaced by a notice announcing the seizure, as part of the law enforcement operation. The botnet was composed of around 280,000 routers since last January and was powered by malware called AVRecon, according to cybersecurity firm Black Lotus Labs, which tracked SocksEscort and worked with law enforcement in the takedown operation.“This botnet posed a significant threat, as it was marketed exclusively to criminals,” the company wrote in its post about the takedown. “Notably, over half of its victims were located in the United States or the United Kingdom, enabling attackers to conduct highly targeted operations.”In 2023, Black Lotus Labs called SocksEscort “one of the largest botnets targeting small-office/home-office (SOHO) routers seen in recent history.” At the time, cybersecurity journalist Brian Krebs reported that SocksEscort was born in 2009 as a Russian-language service selling access to thousands of hacked computers.Topics Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.Actively scaling? Fundraising? Planning your next launch?TechCrunch Founder Summit 2026 delivers tactical playbooks and direct access to 1,000+ founders and investors who are building, backing, and closing.Register by March 13 to save up to $300. DOGE employee stole Social Security data and put it on a thumb drive, report says Meta acquired Moltbook, the AI agent social network that went viral because of fake posts Google rolls out new Gemini capabilities to Docs, Sheets, Slides, and Drive Yann LeCun’s AMI Labs raises $1.03B to build world models Anthropic launches code review tool to check flood of AI-generated code A roadmap for AI, if anyone will listen OpenAI hardware exec Caitlin Kalinowski quits in response to Pentagon deal © 2026 TechCrunch Media LLC.

Read Original

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.