DOJ Disrupts SocksEscort Network Linked to Crypto Fraud

A court-authorized international law enforcement operation led by the U.S. Department of Justice has disrupted SocksEscort, a large residential proxy network that allegedly exploited thousands of internet routers worldwide to facilitate cybercrime and financial fraud.

Authorities said the U.S. government executed seizure warrants against dozens of internet domains registered in the United States that were allegedly connected to the criminal infrastructure. The announcement was made by U.S. Attorney Eric Grant.

According to court documents, the SocksEscort network infected home and small business routers with malware, allowing operators to redirect internet traffic through compromised devices

The network then sold access to these infected routers as proxy services to customers seeking to hide their true locations online.

Investigators said the service had been operating since at least the summer of 2020 and offered access to roughly 369,000 IP addresses at various points

As of February 2026, the SocksEscort platform listed about 8,000 infected routers available for purchase, including around 2,500 located in the United States.

Cybercriminals allegedly used the proxy network to conceal their identities while carrying out a range of fraudulent activities. These included account takeovers targeting U.S. bank accounts and cryptocurrency platforms, as well as schemes involving fraudulent unemployment insurance claims.

Authorities said the crimes caused millions of dollars in losses to victims. Among the cases cited by investigators was a New York resident who lost approximately $1 million in cryptocurrency from an exchange account

In another case, a manufacturing company in Pennsylvania lost $700,000, while current and former U.S. service members using Military Star credit cards were defrauded of about $100,000.

The operation involved coordinated action by international partners, with law enforcement agencies in Austria, France, and the Netherlands helping dismantle key SocksEscort servers.

The investigation is being led by the Federal Bureau of Investigation Sacramento Field Office, along with the Department of Defense Office of Inspector General’s Defense Criminal Investigative Service and IRS Criminal Investigation.

Authorities said the operation highlights the growing importance of international cooperation in combating cybercrime networks that exploit global digital infrastructure.

Your web3 identity + services + payments in one single link. Get your pay3.so link today.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

已停运交易所 BITGIN 洗钱案主犯在中国台湾被起诉,涉案金额逾 1.5 亿新台币

台湾检方起诉加密货币交易所"币竟"及其负责人等10人,因涉嫌与诈骗集团合作,实施诈骗和洗钱,涉及46名受害者,诈骗金额逾1.5亿元。张氏兄妹可能面临12年徒刑。

GateNews2h ago

CFTC Issues Guidance That Could Ignite Massive Prediction Markets Expansion

U.S. regulators move to rein in fast-growing prediction markets as event-based derivatives gain traction, with the CFTC warning exchanges to strengthen surveillance, prevent manipulation, and ensure new contracts tied to real-world outcomes meet federal trading rules. CFTC Issues New Guidance

Coinpedia2h ago

山东警方破获首起涉虚拟货币地下钱庄案,锁定12名嫌疑人及100余个资金账户

山东省德州市公安局女警李伟伟在处理电信诈骗案件中发现新型「传统地下钱庄+虚拟货币」犯罪模式,成功锁定12名嫌疑人和多个资金账户,告破首起涉及虚拟货币的地下钱庄案。

GateNews3h ago

Mỹ và châu Âu triệt phá mạng proxy độc hại Socksescort

U.S. and European officials dismantled the Socksescort proxy network using AVRecon malware, seizing over 369,000 compromised devices. The operation led to the recovery of millions in lost funds, highlighting ongoing vulnerabilities in home routers and the need for improved cybersecurity measures.

TapChiBitcoin5h ago

Judge Rejects RICO Claims in Lawsuit Over Pastor-Led Crypto Ponzi Scheme

A federal judge dismissed RICO claims in a class-action lawsuit against pastor Eddy Alexandre, tied to a crypto Ponzi scheme. Victims can amend their complaint. Alexandre, guilty of commodities fraud, owes substantial penalties and restitution.

Decrypt12h ago

Tether 冻结 Tron 链上某地址约 1200 万枚 USDT

3月14日,Tether冻结了一个Tron链地址持有的11,960,680枚USDT,使用智能合约的黑名单功能。这类冻结通常因洗钱、诈骗等原因触发,自2023年以来,Tether已累计冻结超42亿美元的USDT。

GateNews16h ago
Comment
0/400
No comments