Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Botnet Takedown topic
No spam. Unsubscribe anytime.
FBI, Europol and partners disrupt SocksEscort proxy service in Operation Lightning
Summary
On March 12 the FBI, Europol and international partners announced Operation Lightning, a takedown of the SocksEscort proxy service that relied on malware-infected home and small-business routers; authorities seized infrastructure, froze $3.5 million in crypto and published indicators for defenders.
Get email alerts on the Botnet Takedown topic
No spam. Unsubscribe anytime.
On March 12 federal and international investigators announced Operation Lightning, a coordinated disruption of SocksEscort, a criminal residential-proxy service that trafficked access to malware‑infected home and small‑business routers.
Brett Leatherman, assistant director for the FBI Cyber Division, said SocksEscort had operated since about 2009 and "offered access to approximately 369,000 compromised IP addresses across 163 countries" since 2020. As of February, investigators estimated about 8,000 infected routers remained active worldwide, including roughly 2,500 inside the United States.
Authorities seized 34 domains, 23 servers in seven countries, and froze about $3.5 million in cryptocurrency tied to the operation. The FBI also released a FLASH with indicators of compromise and technical details on the AVrecon malware so defenders can hunt for the infection in their environments.
Leatherman warned the infrastructure was used for a range of criminal activity, including routing account takeovers, facilitating ransomware and distributed denial-of-service attacks, and in some cases distributing child sexual abuse material. He cited victim examples: a New York individual lost $1 million in cryptocurrency, a Pennsylvania manufacturer lost $700,000, and U.S. service members were charged about $100,000 through accounts routed via SocksEscort.
Maeve Healy, who manages the FBI’s Global Partnership Program and helped stand up Operation Winter SHIELD, said the takedown reflected months of legal coordination and intelligence sharing with international partners and the Bureau’s forward‑deployed cyber assistant legal attachés (ALATs). She emphasized that those on‑the‑ground relationships enabled the cross‑border work needed to plan and execute the disruption.
The disruption provides temporary relief for victims and imposes costs on the operators, Leatherman said, but noted that groups can reconstitute and defenders must use the provided technical indicators to hunt and mitigate infections in the near term.
The FBI’s FLASH and published indicators are available to network defenders; the Bureau recommends applying those signatures and reviewing device lifecycles and patching practices for routers and edge devices.
No formal criminal outcomes for named suspects were detailed on the call; the announcement focused on infrastructure seizures, technical guidance and urging defenders to act on the indicators released.

