369,000 Routers Still Infected: SocksEscort Is Down, But Your Remote Workers' Edge Isn't Clean
What Happened
Operation Lightning — a multi-agency takedown spanning seven countries — dismantled SocksEscort, a residential proxy botnet that had operated undetected for 17 years. Law enforcement seized 34 domains, 23 servers, and froze $3.5 million in cryptocurrency. The botnet compromised approximately 369,000 IP addresses across 163 countries using AVRecon malware, generating $5.8 million in criminal revenue by selling residential proxy access to cybercriminals.
The C2 infrastructure is down. The malware on infected devices is not. Those routers are still compromised until someone reboots or patches them.
Why This Is Your Problem
Over 25% of infected routers were in the United States. More than 50% of the 280,000 victims identified since early 2025 were in the US and UK. Peak daily infection rates hit 15,000+ devices in January 2025. The statistical probability that none of your remote workers' home routers are in this pool is effectively zero for any organization with more than a few hundred employees.
The attack model targeted consumer-grade residential routers and IoT devices — exactly the equipment your remote workers use to tunnel into your corporate network via VPN. A compromised home router means an attacker-controlled network hop between your endpoint and your perimeter. Your EDR sees the endpoint; your NDR sees your network. Neither sees the router in between.
Immediate Hunting Guidance
Focus your threat hunt on three areas:
- SOCKS proxy traffic patterns on VPN ingress points — AVRecon converted infected routers into SOCKS proxies. Look for anomalous outbound connections from residential IP ranges to unexpected destinations.
- AVRecon IOCs as they're published from law enforcement disclosures. Cross-reference against your SIEM and NDR telemetry for the past 90 days minimum.
- Behavioral anomalies on residential VPN sessions — unusual session durations, off-hours connectivity, or traffic volume spikes from specific remote worker IPs.
Remediation Reality Check
You cannot remotely patch your employees' home routers. Your realistic options are:
- Issue firmware update guidance to all remote employees — with specific instructions for major consumer router brands (Netgear, TP-Link, ASUS, Linksys). Make it simple enough to act on within 24 hours.
- Recommend router reboots as an immediate interim measure — this may clear in-memory malware, though persistent variants require firmware updates.
- Evaluate managed SD-WAN or SASE solutions that reduce dependence on consumer residential equipment for corporate traffic routing.
- Increase monitoring sensitivity on VPN ingress for the next 90 days — successor botnets will emerge quickly given the proven $5.8M revenue model.
What to do
Query SIEM and NDR for AVRecon IOCs and anomalous SOCKS proxy traffic on all VPN ingress points, prioritizing residential IP ranges
Issue router firmware update and reboot guidance to all remote employees by end of week
Establish a 90-day elevated monitoring window on residential VPN sessions for behavioral anomalies