FBI Warns AVrecon Malware Compromised 369,000 Routers Worldwide in Proxy Network Scheme

The Federal Bureau of Investigation (FBI) has released a FLASH to disseminate indicators of compromise (IOCs) and identified tactics, techniques, and procedures (TTPs) associated with AVrecon malware. This malware has been observed targeting routers and other Internet of Things (IOT) devices, located in approximately 163 countries around the world, including the United States. Threat actors have been found to compromise routers, install AVrecon malware, and then sell access to the compromised devices as residential proxies using the SocksEscort residential proxy service. SocksEscort is believed to have compromised and sold access to approximately 369,000 devices since 2020.

The release of this FLASH follows the coordinated takedown of the SocksEscort service through a joint law enforcement operation. This operation was conducted by the FBI and partners at EUROPOL, France’s Office of Anti-Cybercriminalité (OFAC), the Dutch National Police, Austria’s Bundeskriminalamt (BK), the DoD Office of Inspector General’s Defense Criminal Investigative Service (DCIS), and the U.S. Internal Revenue Service (IRS).

Read the full advisory from the FBI here.

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Related Articles

Latest Articles