Articles
Crypto Market Analysis

DOJ and Europol take down SocksEscort network tied to crypto fraud

User Image

Par Anonyme

Créé March 13, 2026|2 mins de lecture
Main Image

Law enforcement agencies seized 34 domains, 23 servers and froze $3.5 million in crypto linked to SocksEscort, a proxy service that hijacked 369,000 devices.

US and European authorities said Thursday they had disrupted SocksEscort, a malicious proxy service used by cybercriminals to hide their identities while carrying out fraud, including cryptocurrency account takeovers.

The DOJ said the service compromised at least 369,000 routers and other internet-connected devices in 163 countries, giving cybercriminals control over proxies that hid their true IP addresses.

The platform reportedly enabled crimes, including bank fraud and cryptocurrency account takeovers, since 2020. In one case cited by prosecutors, a victim in New York lost roughly $1 million in cryptocurrency.

Authorities said they seized 34 domains, disrupted about two dozen servers across seven countries and froze about $3.5 million in cryptocurrency linked to the operation.

To access the proxy service, customers used a payment platform that allowed them to purchase it anonymously with cryptocurrency, according to a statement by Europol.

Investigators estimate that SocksEscort received at least 5 million euros ($5.7 million) from its users.

“Proxy services like ‘SocksEscort’ provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection,” Europol Executive Director Catherine De Bolle said.

“Operations like this show that when investigators connect the dots internationally, the infrastructure behind cybercrime can be exposed and shut down,” she added.

The takedown was part of a coordinated international effort that included law enforcement agencies from Austria, France, the Netherlands, Germany, Hungary, Romania and the US.

The FBI Sacramento Field Office, the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service, and IRS Criminal Investigation Oakland Field Office were among the US agencies involved. Europol and Eurojust provided investigative and operational support for the cross-border operation.

Related: Sweden probes reported leak of e-government platform source code

The DOJ also acknowledged the assistance of Black Lotus Labs, the threat intelligence unit of the US telecom company Lumen Technologies, and the nonprofit organization Shadowserver Foundation, which provided technical intelligence during the investigation.

According to The Hacker News, SocksEscort relied on malware known as AVrecon, details of which were publicly documented by Black Lotus Labs in July 2023.

Magazine: All 21 million Bitcoin is at risk from quantum computers

Source: CoinTelegraph


D'autres articles publiés récemment

Ripple targets EU, wins preliminary MiCA approval from Luxembourg financial regulator
Ripple targets EU, wins preliminary MiCA approval from Luxembourg financial regulator

Crypto Market Analysis

The license will enable Ripple to offer its stablecoin payment systems to European companies and exp...

Crypto market drops as Nasdaq tech selloff spills into digital assets
Crypto market drops as Nasdaq tech selloff spills into digital assets

Bitcoin

Bitcoin lost 2.5% to $62,300 and ether fell more than 4% while $717 million in liquidations amplifie...

Bitcoin volatility looks cheap as $10 billion options settlement nears
Bitcoin volatility looks cheap as $10 billion options settlement nears

Bitcoin

Your day-ahead look for June 23, 2026Source: CoinDesk...

US Senate passes housing bill with CBDC ban until 2030
US Senate passes housing bill with CBDC ban until 2030

Crypto Market Analysis

The Senate voted 85-5 to pass a major housing affordability bill that includes a ban on the Federal ...

Ripple gains preliminary MiCA license ahead of July 1 EU deadline
Ripple gains preliminary MiCA license ahead of July 1 EU deadline

Crypto Market Analysis

Ripple secures preliminary CASP approval in Luxembourg ahead of July 1 MiCA deadline as companies ra...

THORChain resumes trading more than month after $10M exploit
THORChain resumes trading more than month after $10M exploit

Trading Strategies

THORChain resumed all network activity after implementing multiple security upgrades and a vault mig...