Researchers tied the Linux-based AVrecon remote access trojan to SocksEscort, a long-running proxy-for-rent service that monetized hacked residential and small-business devices. Black Lotus Labs described AVrecon as a major botnet targeting SOHO routers and said it had supported residential proxying, password spraying, web-traffic proxying, and ad fraud since at least mid-2021. Spur correlated AVrecon command-and-control infrastructure with SocksEscort callback systems and concluded that the botnet supplied the compromised endpoints rented through the proxy network.
The operation appeared to suffer a major disruption after Black Lotus Labs published its findings, with Spur observing a sharp drop in available proxy endpoints and victim counts after stage-two command-and-control IPs were reportedly blackholed. KrebsOnSecurity reported that the operators responded by blocking traffic and moving infected devices to new infrastructure, while also tracing SocksEscort through earlier proxy brands, forum identities, and a Moldova-linked network connected to domains, proxy-testing services, and a commercial VPN business.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On July 25, Krebs published an investigation tracing SocksEscort's history and suggesting ties to a Moldova-linked operation. The report linked the service to an individual, related proxy-testing domains, and a VPN app business.
Following Lumen's blocking action on July 13, the operators reacted quickly by moving infected systems to new command-and-control infrastructure. Lumen said the shift appeared aimed at preserving botnet control and revenue.
After publishing its AVrecon research, Lumen began blocking traffic to the malware's control servers on July 13. Spur assessed that Lumen's blackholing of stage-two C2 infrastructure explained the collapse in SocksEscort proxy inventory.
On July 12, Black Lotus Labs published research describing AVrecon as a major SOHO-router botnet. The report detailed its use for residential proxying and other malicious activity.
Around July 11, Spur observed a significant downward trend in available SocksEscort endpoints, with the online proxy count roughly halved. Spur also saw victim counts per SocksEscort server drop to zero while proxy control servers still appeared online.
Danny Adamitis of Lumen confirmed that Spur's findings on SocksEscort infrastructure matched Lumen's AVrecon command-and-control data dating back to September 2022. This anchored the linkage between the botnet and the proxy service to at least that month.
Lumen said AVrecon had largely evaded public attention since it was first spotted in mid-2021. The botnet was used for residential proxying, password spraying, web-traffic proxying, and ad fraud.
Krebs reported that SocksEscort began in 2009 as the Russian-language proxy service super-socks[.]com. The SSC/super-socks identity promoted the service on multiple cybercrime forums.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
spur.us
Open sourcekrebsonsecurity.com
Open sourceblog.lumen.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.