SocksEscort is a criminal residential proxy service and botnet operation that monetized large-scale compromise of internet-connected routers and other edge devices by selling access to those devices as residential proxies. The operation is associated with AVrecon malware, which was used to infect primarily home and small-office routers and convert them into proxy nodes that allowed customers to route traffic through victim networks and conceal malicious activity. Reported activity indicates the service compromised hundreds of thousands of devices across more than 160 countries since 2020. The operation relied on exploitation of known vulnerabilities in exposed routers and IoT devices, including remote code execution, command injection, and related flaws, followed by malware deployment to maintain remote access. AVrecon-supported capabilities included establishing remote shell access, downloading and executing additional payloads, updating configuration, and in some cases achieving persistence by flashing custom firmware and disabling normal update mechanisms. The malware ecosystem was modular and supported reinfection and continued control of compromised devices. SocksEscort functioned as cybercrime infrastructure-for-hire rather than a conventional espionage actor. Authorities linked its proxy network to account takeover, banking and cryptocurrency fraud, unemployment fraud, password spraying, ad fraud, marketplace fraud, romance fraud, website exploitation attempts, distributed denial-of-service activity, and support to ransomware operations. The service accepted cryptocurrency payments and marketed proxy access at scale, indicating a financially motivated criminal enterprise centered on anonymization and abuse of compromised residential infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operated a criminal residential proxy network built on compromised home and small-business routers, selling anonymized proxy access to customers for fraud and other illegal activity.
Criminal proxy service that infected residential and small business routers worldwide, turned them into a botnet, and sold access to compromised residential IPs to customers for fraud and other criminal activity.
Operates a botnet of compromised routers and IoT devices infected with AVrecon and monetizes access by selling them as residential proxies; observed supporting ad fraud, website vulnerability exploitation attempts, password spraying, digital marketplace fraud, banking fraud, and romance fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.