Feds Takes Down SocksEscort Proxy Network Used in Global Fraud Schemes

2026-03-12T20:51:45Z00d5086651ab8bf190b6360f08cede079e7027b7941d420e317f4212f179b846
Android banking trojanBeatBankerBell AmbulanceBlackSantaCloudflare Human CheckHR targetingHandalaIran-linked threat actorMicrosoft 365PIXPixRevolutionSocksEscortStryker disruption','Verifone claimsantivirus evasionbotnet takedowncryptocurrency theftdata breachfake CVhealthcare breachlaw enforcementphishingproxy networkreal-time fraudrecruitment-targeted malwaresilent audio loop

What happened

Multiple security developments: European and US agencies dismantled the SocksEscort proxy network built on infected routers and used in global fraud schemes. Attackers are abusing Cloudflare’s Human Check to conceal Microsoft 365 phishing pages that evade AV detection. Bell Ambulance disclosed a data breach affecting 237,830 individuals that exposed personal and medical data. New Android banking trojans are active: PixRevolution intercepts Brazil’s PIX transfers in real time using live operators, and BeatBanker uses a silent audio loop to stay active while stealing crypto, banking credentials,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
00d5086651ab8bf190b6360f08cede079e7027b7941d420e317f4212f179b846
Enrichment time
2026-03-12T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.