Europol and U.S. authorities on Thursday announced an international law enforcement operation targeting a long-standing residential proxy network service called SocksEscort.

Residential proxies serve as an intermediary server between people and the websites they visit in order to make their connections seem like they originate from somewhere else. Cybercriminals use residential proxy networks to disguise their location while distributing malware, hosting phishing infrastructure, and more. SocksEscort infected home and small business routers with malware and then directed internet traffic through them, before selling that access to its customers. 

“Cybercriminals used the access they purchased on SocksEscort to conceal their true originating IP addresses and locations, which furthered frauds like takeovers of U.S. bank and cryptocurrency accounts and fraudulent unemployment insurance claims,” according to the DoJ in a Thursday statement. “These frauds cost Americans millions of dollars.”

“Proxy services like ‘SocksEscort’ provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection."

Law enforcement agencies joined together from Austria, France, the Netherlands, and the U.S. to launch the operation, which led to the seizure of 34 domains and 23 servers in seven countries. The U.S. also froze $3.5 million in cryptocurrency.

According to Europol, the payment platform driving SocksEscort received more than 5 million euros from proxy service customers. According to the U.S. Justice Department, SocksEscort has offered to sell access to around 369,000 different IP addresses across 163 countries since 2020– and as of February 2026, the application has offered up 8,000 infected routers for customers to buy access to.

SocksEscort

Black Lotus Labs, which partnered with the DoJ in taking the proxy network down, said that it was powered by the AVRecon malware, which was first uncovered by researchers in 2023. According to Black Lotus Labs on LinkedIn, over half of the SocksEscort victims were located in the U.S. or UK. 

Credit: Black Lotus Labs

Residential proxy networks have gained significant traction in the cybercrime space over the years and have proved challenging to network defenders trying to detect and block malicious activities. Lately these networks have been targeted in takedown operations: for instance, in January Google announced it had disrupted what it said was one of the largest residential proxy networks in the world, the IPIDEA proxy network.

“Cybercrime thrives on anonymity,” said Catherine de Bolle, executive director of Europol, in a statement on Thursday. “Proxy services like ‘SocksEscort’ provide criminals with the digital cover they need to launch attacks, distribute illegal content and evade detection. By dismantling this infrastructure, law enforcement has disrupted a service that enabled cybercrime on a global scale.”