Feds Takes Down SocksEscort Proxy Network Used in Global Fraud Schemes
2026-03-13T08:51:50Z•058c5f4589c2e6f8cdabdfffb0b0ceea86d8b14c658972cbd49f0544858f8230
0-dayAndroid banking trojanBeatBankerBlackSantaCloudflare Human CheckHR-targetingHandalaIran-linked actorsMicrosoft 365 phishingPixRevolutionSocksEscortbotnetdata breachfraudhealthcare breachmobile malwarepatch Tuesdayphishingproxy networksocial engineering
What happened
Multiple security incidents and research highlights: EU/US law enforcement dismantled the SocksEscort proxy network built on infected routers that facilitated global fraud; attackers are abusing Cloudflare’s ‘Human Check’ to cloak Microsoft 365 phishing pages that evade detection; Bell Ambulance disclosed a data breach affecting 237,830 individuals (personal and medical data exposed); new Android banking trojans—PixRevolution (real‑time theft of Brazil PIX transfers via live operators) and BeatBanker (silent audio loop to persist while stealing crypto and credentials)—are active; BlackSanta is
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 058c5f4589c2e6f8cdabdfffb0b0ceea86d8b14c658972cbd49f0544858f8230
- Enrichment time
- 2026-03-13T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.