/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The US DOJ says RSocks, a Russian botnet used to hijack millions of devices worldwide for use as proxy servers, was disrupted in an international operation

Hello and welcome to Protocol Enterprise! Dan Robinson / The Register : International operation takes down Russian RSOCKS botnet Tweets: @fbisandiego : Russian Botnet Disrupted in International Cyber Operation: The U.S. Department of Justice, along with law enforcement partners in Germany, the Netherlands and the United Kingdom, have dismantled the infrastructure of a Russian botnet. https://www.fbi.gov/... Andrew Thompson / @imposecost : “At three of the victim locations, with consent, investigators replaced the compromised devices with government-controlled computers (i.e., honeypots), and all three were subsequently compromised by RSOCKS.” https://twitter.com/... https://twitter.com/...

The Record Andrea Peterson

Context & Ripple Effects

The DOJ's RSocks disruption is an early entry in what has become a recurring playbook: coordinated international seizures of criminal proxy and botnet infrastructure. The operation paired the DOJ with law enforcement in Germany, the Netherlands and the United Kingdom, and investigators went beyond seizing servers — at three victim locations they swapped compromised devices for government-controlled honeypots.

That template has since been reused at scale: a later DOJ-led operation took down the SocksEscort residential proxy network, and another disrupted four botnets infecting 3M+ devices, including Aisuru and Kimwolf. Between them, the DOJ also seized domains and X accounts behind a Russian AI-enhanced disinformation bot farm — the same coalition-style approach extended from proxies to influence operations.

First-order effects

  • Millions of hijacked consumer and enterprise devices stop serving as rentable proxy exit nodes, cutting off paying customers of the RSocks service overnight.
  • Law enforcement gains a live intelligence foothold: the honeypots installed on victim networks let investigators observe follow-on traffic instead of just killing the botnet.

Second-order effects

  • Buyers who relied on RSocks for anonymized access migrate to competing residential proxy networks, shifting demand — and law enforcement attention — toward the remaining providers like SocksEscort.
  • Each successful multinational takedown lowers the coordination cost of the next one, making the DOJ-plus-partners model the default response rather than a one-off.

Third-order effects

  • If the pattern holds, criminal proxy infrastructure becomes a persistently contested layer of the internet, with law enforcement running rolling disruption campaigns against successive networks — raising operating costs and churn across the entire underground proxy market.

The trend: US-led international takedown operations are evolving from isolated strikes into a standing campaign against criminal botnet and residential-proxy infrastructure.