AVrecon is a Linux-based remote access trojan used to compromise small-office/home-office routers and other internet-exposed IoT and edge devices, then enroll them into a botnet that has been monetized as a residential proxy network under the SocksEscort service. It has been active since at least 2021 and has targeted a large set of router and embedded-device models from multiple networking vendors, primarily on MIPS and ARM architectures. The malware has been associated with large-scale criminal activity including residential proxying, ad fraud, password spraying, website exploitation attempts, and broader fraud enablement.
AVrecon is written in C and supports modular post-compromise control of infected devices. Reported capabilities include maintaining remote access, opening a remote shell, updating configuration, downloading and executing additional payloads, and periodically beaconing to command-and-control infrastructure. On some targets, operators first deploy a loader to assess the environment and determine whether the malware is already present before installing the main payload. The command-and-control framework has been described as modular, allowing operators to add exploit support and manage infected devices at scale.
Initial compromise has been tied to exploitation of known vulnerabilities in internet-facing routers and IoT devices, including remote code execution, command injection, and exposed management-interface weaknesses. Scanning for exposed vulnerable services has been reported as part of distribution. Weak or default credentials have also been assessed as a possible infection path in some cases. Most observed infections have involved SOHO routers, though the broader targeting set includes other edge and IoT devices.
Persistence varies by device and campaign. Some infections are non-persistent and are removed by rebooting the device, while others achieve stronger persistence through modification of device firmware. In more durable cases, operators have reportedly flashed custom firmware containing AVrecon, configured it to launch automatically at startup, and disabled normal update or reflashing mechanisms to hinder removal and preserve long-term access. Re-infection after reboot has also been observed through repeated exploitation of the same exposed vulnerabilities.
The malware’s operational role has been to convert compromised routers into covert proxy nodes while minimizing disruption visible to device owners, enabling long-lived abuse of victim bandwidth and IP reputation. This made AVrecon particularly suitable for residential proxy services that sell access to hijacked devices to third parties. Law enforcement and private-sector reporting linked AVrecon directly to the SocksEscort proxy network, which used infected home and small-business routers worldwide to conceal criminal traffic. The botnet was later disrupted through coordinated remediation and international law-enforcement action.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SocksEscort utilized malware, identified as AVrecon, to infect home and small business routers, including devices from brands like Cisco, D-Link, and Netgear.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Operation Lightning dismantled SocksEscort in March, which ran on hijacked SOHO routers via the AVRecon botnet.
the Dutch National Police and the National Cyber Security Center announced they had taken down a large-scale botnet that had compromised roughly 17 million devices globally - computers, smartphones, and tablets - all funneled through approximately 200 servers physically hosted inside the Netherlands.
Some possible avenues of infection include exploiting weak or default administrative credentials on routers, and outdated, insecure firmware that has known, exploitable security vulnerabilities.
Rebooting alone may not be sufficient to remediate a compromised device, as the FBI noted that some infections may persist through modified firmware and disabled update functionality.
The compromised devices were infected through a vulnerability in the residential modems of a specific brand.
Some possible avenues of infection include exploiting weak or default administrative credentials on routers, and outdated, insecure firmware that has known, exploitable security vulnerabilities.
Spur.us told KrebsOnSecurity that the Internet addresses Lumen tagged as the AVrecon botnet’s “Command and Control” (C2) servers all tie back to a long-running proxy service called SocksEscort.
Les équipements infectés sont ensuite exploités comme proxies résidentiels, ce qui permet aux cybercriminels de mener diverses activités illicites.
SocksEscort — one of the oldest malware proxy services we track ... identify SocksEscort as the malware proxy service tied to this particular botnet based on the C2 infrastructure.
AVrecon malware prompts the infected device to communicate with its designated C2 server over port 8000 every 60 seconds using a custom loop in which AVrecon and the C2 server exchange the words “PING” and “PONG” until the C2 has a command for AVrecon to execute.
Le malware peut également agir comme loader, en téléchargeant et exécutant des charges malveillantes supplémentaires sur les équipements compromis.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously observed botnet that targeted the same D-Link router models later targeted by AryStinger.
A botnet previously affecting the same router models later targeted by AryStinger; it was dismantled by Lumen in 2023.
AryStinger follows the same pattern seen in campaigns such as AVrecon, SocksEscort, and TheMoon.
Mentioned as a prior botnet that targeted the same D-Link router models.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.