DOJ, Europol Freeze $3.5M In Crypto After Dismantling Global Proxy Fraud Network

bitcoinistPublicado a 2026-03-14Actualizado a 2026-03-14

Resumen

US and European authorities dismantled SocksEscort, a global proxy service that used malware (AVrecon) to hijack over 369,000 devices in 163 countries, allowing criminals to hide their locations. The service, operating for years, generated at least $5.7 million from users who paid in cryptocurrency for anonymity. A coordinated law enforcement effort across multiple countries resulted in the seizure of 34 domains, takedown of servers, and freezing of $3.5 million in crypto. The network was linked to various crimes, including a $1 million cryptocurrency theft from a New York resident, bank fraud, and account takeovers.

A New York resident lost close to $1 million in cryptocurrency. That single case became one of the clearest examples of the damage done by SocksEscort — a for-hire proxy service that gave criminals across the globe a way to hide while they stole.

A Network Built On Hijacked Devices

US and European authorities announced Thursday they had shut down SocksEscort after years of operation. The service worked by infecting routers and other internet-connected devices with malware, turning them into cover points that masked the real locations of cybercriminals.

According to the Department of Justice, the network had quietly burrowed into at least 369,000 devices spread across 163 countries. Criminals could then route their attacks through those compromised machines, making them far harder to trace.

The malware at the heart of the operation — known as AVrecon — had been publicly identified by cybersecurity firm Black Lotus Labs as far back as July 2023. The network kept running anyway.

Source: DOJ

The takedown was not a single agency effort. Law enforcement from Austria, France, Germany, Hungary, the Netherlands, Romania, and the US worked the case together.

On the American side, the FBI’s Sacramento Field Office, the IRS Criminal Investigation Oakland Field Office, and the Department of Defense’s Defense Criminal Investigative Service all had a hand in it.

Europol and Eurojust provided cross-border coordination support. Black Lotus Labs and the nonprofit Shadowserver Foundation supplied technical intelligence that helped investigators connect the dots.

Bitcoin is now trading at $70,541. Chart: TradingView

Criminals Paid In Crypto To Stay Anonymous

SocksEscort did not just attract individual bad actors. It ran like a business. Customers paid to access the service, and they did so anonymously — using cryptocurrency to avoid leaving a financial trail.

Based on reports from Europol, the platform pulled in at least 5 million euros, roughly $5.7 million, from its paying users over the course of its run.

Authorities were ultimately able to seize 34 domains, take down about two dozen servers operating across seven countries, and freeze approximately $3.5 million in crypto tied to the operation.

Europol Executive Director Catherine De Bolle said proxy services of this kind give criminals the cover to carry out attacks, move illegal content, and dodge detection. She credited the international cooperation for exposing the infrastructure behind it.

Fraud Stretched From Bank Accounts To Crypto Wallets

The crimes enabled by SocksEscort went beyond any single method. Officials linked the network to bank fraud and cryptocurrency account takeovers dating back to 2020.

The New York victim’s case stood out for its scale, but reports indicate the damage was spread across multiple countries and target types.

Featured image from Pexels, chart from TradingView

Preguntas relacionadas

QWhat was the name of the proxy service dismantled by US and European authorities?

ASocksEscort

QHow many devices were infected by the malware used in the SocksEscort operation according to the Department of Justice?

AAt least 369,000 devices

QWhat was the name of the malware at the heart of the SocksEscort operation?

AAVrecon

QHow much cryptocurrency was frozen by authorities in connection with the SocksEscort network?

AApproximately $3.5 million

QWhich cybersecurity firm had publicly identified the AVrecon malware as far back as July 2023?

ABlack Lotus Labs

Lecturas Relacionadas

Los retiros de Bitcoin continúan: 8 años de almacenamiento en una cartera fría Coldcard terminaron en cero

Retirada de bitcoin continúa: 8 años en cartera fría Coldcard terminan en cero La cartera hardware Coldcard ha sido vulnerada, provocando una nueva oleada de retiradas de fondos de dispositivos afectados. Galaxy Research informa que el volumen total robado asciende a 1.367,05 BTC (unos 88,6 millones de dólares) desde 4.585 direcciones, superando ampliamente los 594,5 BTC reportados inicialmente el 30 de julio de 2026. La mayor parte de lo robado permanece inactiva en las direcciones de los atacantes. El problema no reside en el firmware, que ya fue actualizado por Coinkite, sino en las frases semilla (seed phrases) generadas desde marzo de 2021 debido a un error de programación. Estas frases son fácilmente descifrables, y actualizar el firmware no las cambia. Solo transferir los fondos a una nueva dirección con una nueva frase semilla elimina la vulnerabilidad. El fallo se originó al integrar la biblioteca libNgU, lo que hizo que los dispositivos dejaran de usar el generador de números aleatorios por hardware STM32 y pasaran a usar el generador software Yasmarang, inicializado con datos públicamente accesibles como el número de serie del chip. Afecta a frases semilla creadas en dispositivos Mk2/Mk3 (firmware 4.0.1–4.1.9 y hasta 5.0.3), Mk4/Mk5 (hasta v5.6.0) y Q (hasta v1.5.0Q). Se excluyen aquellas creadas con al menos 50 lanzamientos de dados independientes o una passphrase BIP-39 fuerte y única. Los usuarios deben generar una nueva frase semilla en firmware corregido y transferir sus activos. Un caso ilustrativo es el de un inversor de 39 años que perdió 2 BTC (unos 130.000 dólares) en minutos, ahorrados durante ocho años mediante trabajo físico como protección contra la hiperinflación en su país, con el objetivo de una jubilación anticipada a los 50 años. Su estrategia conservadora de "comprar y mantener en frío" se vio truncada, dejándolo devastado y decidido a abandonar las criptomonedas. Este incidente recuerda vulnerabilidades históricas por generadores de números aleatorios débiles, como la de la biblioteca BitcoinJS (2011-2015), que causó grandes pérdidas. Subraya que el almacenamiento offline no garantiza automáticamente seguridad criptográfica, especialmente cuando la entropía se ve comprometida dentro del propio dispositivo "cerrado".

cryptonews.ruHace 5 hora(s)

Los retiros de Bitcoin continúan: 8 años de almacenamiento en una cartera fría Coldcard terminaron en cero

cryptonews.ruHace 5 hora(s)

Trading

Spot
活动图片