Policy & Regulation
Law enforcement dismantles SocksEscort botnet
A global law enforcement coalition has dismantled the SocksEscort botnet, which allegedly compromised more than 369,000 routers and IoT devices across 163 countries to facilitate criminal activity.
A global coalition of law enforcement agencies shut down the SocksEscort botnet on Wednesday. The operation targeted SocksEscort, a service built on a botnet—which is a network of compromised private computers and devices controlled as a group. According to Europol, the botnet allegedly compromised more than 369,000 routers and Internet of Things (IoT) devices across 163 countries. The Department of Justice announced the takedown operation on Thursday, noting that the infected devices have been disconnected from the service. The Department of Justice stated that the crimes facilitated by SocksEscort cost Americans millions of dollars, which included hacking into bank and cryptocurrency accounts and filing fraudulent unemployment insurance claims.
The botnet was powered by malware called AVRecon, according to cybersecurity firm Black Lotus Labs, which tracked the botnet and collaborated with law enforcement. The service targeted small-office/home-office (SOHO) routers, allowing customers to rent access to these infected devices to mask their IP addresses. According to Europol, “Customers of the criminal service paid for licenses to abuse these infected devices, hiding their original IP addresses to engage in various criminal activities,” while the modems’ owners would not be aware that their IP addresses were being used for illegitimate activities. Black Lotus Labs reported that the botnet was composed of around 280,000 routers since last January.
The service has a long history. Cybersecurity journalist Brian Krebs reported that SocksEscort was born in 2009 as a Russian-language service selling access to thousands of hacked computers. Over its lifespan, the botnet was marketed exclusively to criminals. Black Lotus Labs, a cybersecurity firm, noted that the botnet posed a significant threat because it was marketed exclusively to criminals, and that over half of its victims were located in the United States or the United Kingdom, enabling attackers to conduct highly targeted operations. Europol reported that the service was used to facilitate ransomware, distributed denial of service (DDoS) attacks, and the distribution of child sexual abuse material (CSAM).
Why it matters
The takedown of the SocksEscort botnet disrupts a major criminal service that compromised hundreds of thousands of routers globally to facilitate ransomware, DDoS attacks, and other illegal activities. The operation highlights the vulnerability of small-office and home-office routers to global cybercriminal networks.