Feds Takes Down SocksEscort Proxy Network Used in Global Fraud Schemes
2026-03-12T20:51:45Z•00d5086651ab8bf190b6360f08cede079e7027b7941d420e317f4212f179b846
Android banking trojanBeatBankerBell AmbulanceBlackSantaCloudflare Human CheckHR targetingHandalaIran-linked threat actorMicrosoft 365PIXPixRevolutionSocksEscortStryker disruption','Verifone claimsantivirus evasionbotnet takedowncryptocurrency theftdata breachfake CVhealthcare breachlaw enforcementphishingproxy networkreal-time fraudrecruitment-targeted malwaresilent audio loop
What happened
Multiple security developments: European and US agencies dismantled the SocksEscort proxy network built on infected routers and used in global fraud schemes. Attackers are abusing Cloudflare’s Human Check to conceal Microsoft 365 phishing pages that evade AV detection. Bell Ambulance disclosed a data breach affecting 237,830 individuals that exposed personal and medical data. New Android banking trojans are active: PixRevolution intercepts Brazil’s PIX transfers in real time using live operators, and BeatBanker uses a silent audio loop to stay active while stealing crypto, banking credentials,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 00d5086651ab8bf190b6360f08cede079e7027b7941d420e317f4212f179b846
- Enrichment time
- 2026-03-12T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.