FBI Warns of AVrecon Malware Targeting Network Devices Across 163 Countries
ID: 4ddbf444-2c36-5624-8d24-ace3b6647c31
STIX ID: report--4ddbf444-2c36-5624-8d24-ace3b6647c31
Feed Name: The Cyber Express
**Executive summary:** The FBI found AVrecon malware being used by the SocksEscort criminal service to infect vulnerable SOHO routers (targeting ~1,200 device models) and convert roughly 369,000 devices into a global residential proxy network used for fraud, password attacks, and other criminal activity; persistence via firmware flashing and modular C2 functionality make this a widespread and resilient threat, and defenders are advised to apply firmware updates, replace EoL devices, disable remote admin, and monitor known IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
