Key Takeaways: Europol and other law enforcement agencies tore up the SocksEscort proxy network that had spread to over 369,000 routers and IoT devices across theKey Takeaways: Europol and other law enforcement agencies tore up the SocksEscort proxy network that had spread to over 369,000 routers and IoT devices across the

Europol Freezes $3.5M in Crypto as Global Crackdown Dismantles Massive Proxy Botnet

2026/03/13 18:05
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Key Takeaways:

  • Europol and other law enforcement agencies tore up the SocksEscort proxy network that had spread to over 369,000 routers and IoT devices across the world.
  • Authorities confiscated 34 domains, 23 servers and also froze $3.5 million worth of cryptocurrency associated with the operation.
  • The malicious service sold proxy access paid with crypto, generating more than €5 million from customers.

European and U.S. authorities have taken down a large cybercrime infrastructure that relied on infected home routers and IoT devices. This coordinated bust hunted down a proxy service much relied upon by a large number of crooks to conceal their footprints during the pulling off of Internet attacks.

It demonstrates the increasing connection between crypto payments and decentralized technology and international cybersecurity investigations.

International Operation Targets SocksEscort Network

Law enforcement agencies across Europe and the United States implemented a coordinated campaign named Operation Lightning March 11th 2026. This campaign focuses on dismantling the proxy platform called SocksEscort. According to the investigators, it exploited vulnerabilities in household routers.

Competent authorities identified that this network has accessed more than 369,000 devices in 163 countries. These infected routers and IoT devices have been utilized to provide anonymous proxy connections for paying customers.

During the action, investigators seized 34 domain names and 23 servers located in seven countries. At the same time, U.S. authorities froze approximately $3.5 million in cryptocurrency connected to the service.

Officials also disconnected infected modems from the network, effectively shutting down access to the proxy system used by criminal customers.

Read More: Coinbase Launches Regulated Crypto Futures in 26 European Markets With 10x Leverage

Malware-Infected Routers Powered Global Botnet

The investigation was initiated in June 2025 by the Joint Cyberaction Task Force (J-CAT) of Europol. Analysts discovered a massive botnet constructed of compromised devices, the majority of them being only home routers.

Vulnerabilities Allowed Large-Scale Exploitation

The bad actors found a vulnerability of a particular modem brand, which was learnt by the investigators. Malware installed on those devices quietly turned them into nodes of a global proxy network.

Once infected, the routers allowed criminals to route internet traffic through unsuspecting users’ IP addresses. Device owners typically had no idea their internet connection was being used for illegal activity.

The proxy network enabled a range of crimes, including ransomware operations, distributed denial-of-service attacks, and the spread of illegal content.

Customers paid for licenses to access the proxy infrastructure. Payments were made through a platform that allowed anonymous transactions using cryptocurrency.

The authorities indicate that the payment system based on that proxy also collected more than €5 million crypto, which had been sent by the users.

Read More: MiCA Reality: EU Countries Set to Lead CASP Licensing in the New Era

Europol Coordinates Intelligence and Crypto Tracking

The lead player was Europol who led the investigation. They assisted in matching partnering agencies in terms of intel sharing, malware inspection, traffic sniffing, and crypto tracing. During the day of action, the action was supported by a Virtual Command Post on the HQ of EuropaL in Hague to ensure the smooth flow of chatter between the involved countries was maintained.

Participating authorities included law enforcement bodies from Austria, France, the Netherlands, Germany, Hungary, Romania, and the United States, among others. U.S. agencies involved in the case included the Department of Justice, the FBI, and IRS Criminal Investigation.

The post Europol Freezes $3.5M in Crypto as Global Crackdown Dismantles Massive Proxy Botnet appeared first on CryptoNinjas.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
Wall Street expert predicts 80% Tesla stock crash in 2026

Wall Street expert predicts 80% Tesla stock crash in 2026

The post Wall Street expert predicts 80% Tesla stock crash in 2026 appeared on BitcoinEthereumNews.com. Tesla (NASDAQ: TSLA) FSD – the autonomous driving technology
Share
BitcoinEthereumNews2026/03/16 22:04
The Economics of Self-Isolation: A Game-Theoretic Analysis of Contagion in a Free Economy

The Economics of Self-Isolation: A Game-Theoretic Analysis of Contagion in a Free Economy

Exploring how the costs of a pandemic can lead to a self-enforcing lockdown in a networked economy, analyzing the resulting changes in network structure and the existence of stable equilibria.
Share
Hackernoon2025/09/17 23:00