Feds Takes Down SocksEscort Proxy Network Used in Global Fraud Schemes

2026-03-13T08:51:50Z058c5f4589c2e6f8cdabdfffb0b0ceea86d8b14c658972cbd49f0544858f8230
0-dayAndroid banking trojanBeatBankerBlackSantaCloudflare Human CheckHR-targetingHandalaIran-linked actorsMicrosoft 365 phishingPixRevolutionSocksEscortbotnetdata breachfraudhealthcare breachmobile malwarepatch Tuesdayphishingproxy networksocial engineering

What happened

Multiple security incidents and research highlights: EU/US law enforcement dismantled the SocksEscort proxy network built on infected routers that facilitated global fraud; attackers are abusing Cloudflare’s ‘Human Check’ to cloak Microsoft 365 phishing pages that evade detection; Bell Ambulance disclosed a data breach affecting 237,830 individuals (personal and medical data exposed); new Android banking trojans—PixRevolution (real‑time theft of Brazil PIX transfers via live operators) and BeatBanker (silent audio loop to persist while stealing crypto and credentials)—are active; BlackSanta is

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
058c5f4589c2e6f8cdabdfffb0b0ceea86d8b14c658972cbd49f0544858f8230
Enrichment time
2026-03-13T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.