DOJ, Europol Freeze $3.5M In Crypto After Dismantling Global Proxy Fraud Network

bitcoinistОпубликовано 2026-03-14Обновлено 2026-03-14

Введение

US and European authorities dismantled SocksEscort, a global proxy service that used malware (AVrecon) to hijack over 369,000 devices in 163 countries, allowing criminals to hide their locations. The service, operating for years, generated at least $5.7 million from users who paid in cryptocurrency for anonymity. A coordinated law enforcement effort across multiple countries resulted in the seizure of 34 domains, takedown of servers, and freezing of $3.5 million in crypto. The network was linked to various crimes, including a $1 million cryptocurrency theft from a New York resident, bank fraud, and account takeovers.

A New York resident lost close to $1 million in cryptocurrency. That single case became one of the clearest examples of the damage done by SocksEscort — a for-hire proxy service that gave criminals across the globe a way to hide while they stole.

A Network Built On Hijacked Devices

US and European authorities announced Thursday they had shut down SocksEscort after years of operation. The service worked by infecting routers and other internet-connected devices with malware, turning them into cover points that masked the real locations of cybercriminals.

According to the Department of Justice, the network had quietly burrowed into at least 369,000 devices spread across 163 countries. Criminals could then route their attacks through those compromised machines, making them far harder to trace.

The malware at the heart of the operation — known as AVrecon — had been publicly identified by cybersecurity firm Black Lotus Labs as far back as July 2023. The network kept running anyway.

Source: DOJ

The takedown was not a single agency effort. Law enforcement from Austria, France, Germany, Hungary, the Netherlands, Romania, and the US worked the case together.

On the American side, the FBI’s Sacramento Field Office, the IRS Criminal Investigation Oakland Field Office, and the Department of Defense’s Defense Criminal Investigative Service all had a hand in it.

Europol and Eurojust provided cross-border coordination support. Black Lotus Labs and the nonprofit Shadowserver Foundation supplied technical intelligence that helped investigators connect the dots.

Bitcoin is now trading at $70,541. Chart: TradingView

Criminals Paid In Crypto To Stay Anonymous

SocksEscort did not just attract individual bad actors. It ran like a business. Customers paid to access the service, and they did so anonymously — using cryptocurrency to avoid leaving a financial trail.

Based on reports from Europol, the platform pulled in at least 5 million euros, roughly $5.7 million, from its paying users over the course of its run.

Authorities were ultimately able to seize 34 domains, take down about two dozen servers operating across seven countries, and freeze approximately $3.5 million in crypto tied to the operation.

Europol Executive Director Catherine De Bolle said proxy services of this kind give criminals the cover to carry out attacks, move illegal content, and dodge detection. She credited the international cooperation for exposing the infrastructure behind it.

Fraud Stretched From Bank Accounts To Crypto Wallets

The crimes enabled by SocksEscort went beyond any single method. Officials linked the network to bank fraud and cryptocurrency account takeovers dating back to 2020.

The New York victim’s case stood out for its scale, but reports indicate the damage was spread across multiple countries and target types.

Featured image from Pexels, chart from TradingView

Связанные с этим вопросы

QWhat was the name of the proxy service dismantled by US and European authorities?

ASocksEscort

QHow many devices were infected by the malware used in the SocksEscort operation according to the Department of Justice?

AAt least 369,000 devices

QWhat was the name of the malware at the heart of the SocksEscort operation?

AAVrecon

QHow much cryptocurrency was frozen by authorities in connection with the SocksEscort network?

AApproximately $3.5 million

QWhich cybersecurity firm had publicly identified the AVrecon malware as far back as July 2023?

ABlack Lotus Labs

Похожее

380,000 Apps Exposed, 2,000+ Apps Leaked Secrets: AI Programming Turns 'Intranet' into Public Internet

Israeli cybersecurity firm RedAccess uncovered a severe data exposure trend linked to "vibe coding" or AI-powered software development tools. Their research found approximately 38,000 publicly accessible web applications built with platforms like Lovable, Base44, Netlify, and Replit. Of these, an estimated 2,000 apps exposed sensitive corporate and personal data, including medical records, financial information, internal strategic documents, and customer chat logs. In some cases, access even granted administrative privileges. The core issue stems from default privacy settings that make applications public by default, combined with a lack of built-in security controls (like authentication) in the AI-generated code. This allows employees without security expertise—"citizen developers"—to easily create and deploy applications that bypass standard corporate security reviews. The exposed apps, often indexed by search engines, are trivially discoverable. While some platform providers (Replit, Lovable, Wix/Base44) argue that security configuration is the user's responsibility and question the validity of some findings, security researchers confirm the widespread reality of such exposures. This pattern, also noted in prior studies, highlights a critical security gap as AI democratizes app creation, potentially leading to massive, unintentional data leaks.

marsbit26 мин. назад

380,000 Apps Exposed, 2,000+ Apps Leaked Secrets: AI Programming Turns 'Intranet' into Public Internet

marsbit26 мин. назад

Attracting Global Capital, Asia's New 'Super Cycle' Is Unfolding

Investors are turning to Asia as the next frontier for global equity growth, with a new "super cycle" unfolding across the region. Driven by the AI revolution, Asian markets, particularly South Korea, have seen significant rallies. According to Morgan Stanley analysis, the underlying drivers of Asia's industrial cycle are shifting from traditional sectors like real estate and manufacturing to massive investments in AI infrastructure, energy security and transition, and supply chain resilience. Fixed asset investment in Asia is projected to grow from around $11 trillion in 2025 to $16 trillion by 2030, with a 7% annual growth rate from 2026-2030. The AI wave is a primary catalyst, driving immense capital expenditure for chips, servers, data centers, and power systems. Asia is central to this hardware supply chain. In China, AI investment is focused on building a full-system domestic capability, with the local AI chip market potentially reaching $86 billion by 2030. Beyond AI, China's export story is expanding from EVs and batteries to robotics. The country already captures about half of new global industrial robot demand and over 90% of humanoid robot shipments. This growth phase mirrors the early stages of China's EV export boom. Simultaneously, energy security investments, spurred by AI's massive power needs, are rising, with China benefiting from its leadership in solar, batteries, and EVs. Regional defense spending is also increasing structurally, supporting demand for advanced manufacturing. The main beneficiaries are China, South Korea, and Japan, positioned in core supply chain areas. However, risks remain, including potential overcapacity, profit margin pressures from competition, persistent technological restrictions, geopolitical friction, and workforce displacement due to AI-driven automation. Market volatility is also expected to increase as investor expectations diverge on the realization of these capital investment and export themes.

marsbit27 мин. назад

Attracting Global Capital, Asia's New 'Super Cycle' Is Unfolding

marsbit27 мин. назад

Funding Weekly Report | 14 Public Funding Events, Kalshi Completes $10B New Funding Round at $220B Valuation Led by Coatue Management

Weekly Funding Roundup: 14 Deals and $10.49B+ in Total Funding, Led by Kalshi's $1B Round Last week (5.4-5.10) saw 14 notable funding events in the global blockchain ecosystem, raising over $10.49 billion in total. Key highlights include Kalshi, a prediction market platform, securing a $1 billion round led by Coatue Management, reaching a $22 billion valuation. The platform now boasts ~2 million MAUs and $178B in annualized trading volume. In DeFi, regulated on-chain reinsurer OnRe raised $5 million in Series A funding, and Bitcoin-backed credit protocol Saturn Credit completed a $2 million seed round. For Infrastructure & Tools, OpenTrade raised $17 million to expand its stablecoin yield infrastructure, and RWA platform Balcony secured $12.7 million to deploy its property settlement service in the US. Centralized Finance saw one deal: AI-driven trading platform Stockcoin.ai completed a seed round led by Amber Group. In the prediction market sector alongside Kalshi, AI-powered platform Elastics raised $2 million. Other notable deals include SC Ventures' strategic investment in crypto market maker GSR and Centrifuge securing a "seven-figure" investment from Coinbase to become a core RWA partner for Base. On the investor side, Haun Ventures raised a new $1 billion fund targeting crypto and AI, and Multi Investment raised ~$616 million to focus on blockchain and Web3 investments.

marsbit1 ч. назад

Funding Weekly Report | 14 Public Funding Events, Kalshi Completes $10B New Funding Round at $220B Valuation Led by Coatue Management

marsbit1 ч. назад

Торговля

Спот
Фьючерсы
活动图片