AVRecon Botnet Leveraging Compromised Routers to Fuel Illegal Proxy Service

Share:

More details have emerged about a botnet called AVRecon, which has been observed making use of compromised small office/home office (SOHO) routers as part of a multi-year campaign active since at least May 2021.

AVRecon was first disclosed by Lumen Black Lotus Labs earlier this month as malware capable of executing additional commands and stealing victim’s bandwidth for what appears to be an illegal proxy service made available for other actors. It has also surpassed QakBot in terms of scale, having infiltrated over 41,000 nodes located across 20 countries worldwide.

The malware has been used to create residential proxy services to shroud malicious activity such as password spraying, web-traffic proxying, and ad fraud, the researchers said in the report.

This has been corroborated by new findings from KrebsOnSecurity and Spur.us, which last week revealed that AVrecon is the malware engine behind a 12-year-old service called SocksEscort, which rents hacked residential and small business devices to cybercriminals looking to hide their true location online.

The basis for the connection stems from direct correlations between SocksEscort and AVRecon’s command-and-control (C2) servers. SocksEscort is also said to share overlaps with a Moldovan company named Server Management LLC that offers a mobile VPN solution on the Apple Store called HideIPVPN.

Black Lotus Labs told The Hacker News that the new infrastructure it identified in connection with the malware exhibited the same characteristics as the old AVrecon C2s.

The new SocksEscort nodes, which shifted during the second week of July (Source: Lumen Black Lotus Labs)

We assess that the threat actors were reacting to our publication and null-routing their infrastructure, and attempting to maintain control over the botnet, the company said. This suggests the actors wish to further monetize the botnet by maintaining some access and continue enrolling users in the SocksEscort ‘proxy as a service.’

Routers and other edge appliances have become lucrative attack vectors in recent years owing to the fact that such devices are infrequently patched against security issues, may not support endpoint detection and response (EDR) solutions, and are designed to handle higher bandwidths.

AVRecon also poses a heightened threat for its ability to spawn a shell on a compromised machine, potentially enabling threat actors to obfuscate their own malicious traffic or retrieve further malware for post-exploitation.

While these bots are primarily being added to the SocksEscort proxy service, there was embedded functionality within the file to spawn a remote shell, the researchers said.

This could allow the threat actor the ability to deploy additional modules, so we suggest that managed security providers attempt to investigate these devices in their networks, while home users should power-cycle their devices.

 

(c) Thin

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:30 pm, May 18, 2025
weather icon 13°C
L: 12° | H: 14°
overcast clouds
Humidity: 75 %
Pressure: 1019 mb
Wind: 4 mph NE
Wind Gust: 10 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:04 am
Sunset: 8:49 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
12° | 14°°C 0 mm 0% 10 mph 82 % 1022 mb 0 mm/h
Tue May 20 10:00 pm
weather icon
9° | 21°°C 0 mm 0% 8 mph 76 % 1022 mb 0 mm/h
Wed May 21 10:00 pm
weather icon
12° | 20°°C 1 mm 100% 6 mph 88 % 1020 mb 0 mm/h
Thu May 22 10:00 pm
weather icon
8° | 15°°C 0.09 mm 9% 10 mph 78 % 1023 mb 0 mm/h
Fri May 23 10:00 pm
weather icon
7° | 18°°C 0 mm 0% 9 mph 80 % 1023 mb 0 mm/h
Tomorrow 1:00 am
weather icon
12° | 12°°C 0 mm 0% 7 mph 74 % 1019 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 12°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 77 % 1021 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 7 mph 52 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
17° | 17°°C 0 mm 0% 8 mph 44 % 1020 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
19° | 19°°C 0 mm 0% 10 mph 40 % 1020 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 6 mph 64 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,544.46
1.05%
Ethereum(ETH)
€2,157.31
-3.16%
Tether(USDT)
€0.90
0.01%
XRP(XRP)
€2.14
1.51%
Solana(SOL)
€150.48
0.33%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.201257
3.73%
Shiba Inu(SHIB)
€0.000013
2.26%
Pepe(PEPE)
€0.000012
7.40%
Peanut the Squirrel(PNUT)
€0.294814
9.33%
Scroll to Top