Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

5socks.net: 20 years of proxy crime, 2004 to seizure

Dancho DanchevBy Dancho DanchevJuly 31, 2026Updated:July 31, 2026No Comments9 Mins Read39 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
5socks.net: 20 years of proxy crime, 2004 to seizure, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

5socks.net sold access to compromised residential IP addresses for more than twenty years before the FBI and the Dutch National Police seized the domain in May 2025. Four men, three Russian nationals and one Kazakhstani, were indicted for running it alongside Anyproxy.net, a business the U.S. Department of Justice says took in more than $46 million. This is where the service came from, and how a question I asked in 2010 finally got answered.

Who was behind 5socks.net?

The service came out of the Russian hacking scene of the mid 2000s, not out of a commercial proxy business.

Historical domain registration records for 5socks.net, and the contact form on the site itself, list a Russian individual, Vladimir Belyankin. Those records establish who registered the domain in the mid 2000s. They do not establish who operated the service in the years that followed, and Belyankin is not among the four people charged by the Department of Justice in 2025.

The more productive pivot is the address used in that registration record, [email protected]. Whoever registered 5socks.net used an email address belonging to another project of theirs, the Gh0st Security Team, whose site sat at gst.void.ru and which public records show was active in 2005. This is a standard registrant-to-project pivot, the same technique covered in our domain and subdomain reconnaissance guide, and in this case it ties a commercial proxy service directly to a named hacking crew.

Archived Gh0st Security Team website at gst.void.ru, the project linked to the 5socks.net domain registration email address
The Gh0st Security Team site at gst.void.ru, reachable through the [email protected] address used to register 5socks.net. Public records place the group as active in 2005.

Although for today’s hacking groups jumping into a commercial cybercrime service offering might look unremarkable, back then for a Russian hacking group to launch one was innovative. The underground now runs on subscriptions, tiered pricing and support channels. In 2005 that model was still being invented, and 5socks.net was one of the places it was invented.

What 5socks.net actually sold

5socks.net sold timed access to a rotating pool of SOCKS proxies running on other people’s internet connections.

Back in the day when I was doing cybercrime research on my own in 2010, the service stood as a cornerstone to some, while the majority of others were presuming that it was used primarily for anonymization. It was one of the most heavily advertised offerings of its kind on prominent Russian cybercrime forums.

Among the few things that personally impressed me when I originally analyzed and profiled the service was the level and degree of geolocation applied to the available IPs, which was relatively advanced and sophisticated for its time. The member panel did not simply list addresses. It listed country, state, city, connection type, uptime, time since last check and response speed, and it let a buyer sort the inventory by any of them.

5socks.net member panel dated 21 October 2008 showing 1,610 socks online, filtered to United States hosts, listing residential Comcast, Charter, RoadRunner and Pacbell hostnames with city-level geolocation and uptime
The 5socks.net member panel on 21 October 2008, reporting 1,610 socks online and filtered to United States hosts. Sorting, city-level geolocation and per-host uptime were all buyer-facing features.

The hostnames in that listing are the giveaway. Comcast, Charter, RoadRunner, SBC and Pacbell reverse-DNS entries in Concord, Orange Park, Palm Desert, Houston, Albany, Monterey, Staten Island, Bucyrus, Opelousas, Miami and Fresno. Those are ordinary domestic broadband lines in American towns, not data-centre ranges.

The question nobody could answer in 2010

One question logically emerged back then. How is it possible that a Russia based proxy-as-a-service would acquire and have access to thousands of available U.S. based IP addresses?

There were only two answers. Either the users of those connections were knowingly participating with their IPs and bandwidth, or the service was obtaining access by other means, for instance using botnets.

The consent explanation never held up well. Nobody was running a paid opt-in bandwidth programme in Concord, North Carolina in 2008 that would have terminated on a Russian-language forum’s proxy panel, and the buyer-side pricing was far too low to fund one. The botnet explanation fit the evidence better, but in 2010 it was a reading of the data, not a finding. Without visibility into the infected devices themselves, it stayed a hypothesis for fifteen years.

What Operation Moonlander found

The May 2025 takedown answered it. On 9 May 2025 the Department of Justice unsealed a domain seizure warrant alongside an indictment charging four foreign nationals, announced by U.S. Attorney Clint Johnson for the Northern District of Oklahoma.

Alexey Viktorovich Chertkov, Kirill Vladimirovich Morozov and Aleksandr Aleksandrovich Shishkin, all Russian nationals, and Dmitriy Rubtsov, a Kazakhstani national, were charged with conspiracy and damage to protected computers. Chertkov and Rubtsov face an additional count of false registration of a domain name, on the allegation that they falsely identified themselves when registering and using 5socks.net and anyproxy.net. All four reside outside the United States.

The mechanism described in the indictment is the botnet answer. According to the DoJ, a botnet was created by infecting older-model wireless internet routers worldwide, including in the United States, using malware, without the owners’ knowledge. That malware allowed the routers to be reconfigured so unauthorized third parties could be granted access, and the devices were then made available for sale as proxy servers on the two websites. Both domains were managed by a company headquartered in Virginia and hosted on servers worldwide.

The commercial detail matches the 2008 panel closely. Court documents put more than 7,000 proxies advertised for sale worldwide, on subscriptions ranging from $9.95 to $110 per month. The site’s own slogan, “Working since 2004!”, is what prosecutors cite for the twenty-year runtime. The defendants are believed to have amassed more than $46 million from selling access to the infected routers.

The operation ran as the FBI plus the Dutch National Police, the Netherlands Public Prosecution Service and the Royal Thai Police, with Lumen Technologies’ Black Lotus Labs providing network visibility. Both domains now serve seizure notices.

What the infected fleet actually looked like

Black Lotus Labs tracked the network for over a year before the takedown, and its findings fill in what the criminal panel never showed.

The team observed a weekly average of around 1,000 unique bots contacting command-and-control infrastructure located in Turkey. Over half the victims were in the United States, with Canada and Ecuador next. The device population was IoT and end-of-life hardware, and Lumen’s assessment was that the operators were not burning zero-days or one-days on it. They relied on exploits that had been public for years, which is exactly what a focus on unpatched and end-of-life devices implies. Black Lotus Labs deliberately withheld malware detail on the grounds that the devices are easy to re-exploit by others.

That is the shape of a durable business, not a spectacular one. A thousand concurrent bots is small next to the botnets that make headlines. It was enough, because what the buyers were paying for was never volume. It was residential legitimacy.

Why this still matters in 2026

The 5socks.net model did not die with the seizure, because the demand behind it did not.

With the cybercrime ecosystem currently overpopulated with similar commercial propositions, the popularity of this one service is only scratching the surface of a bigger problem, where today, just like a decade ago, cybercriminals can truly forward the risk for their malicious and fraudulent online actions to a third-party user who is unsuspecting and unknowingly participating in a botnet, and whose home or office based IP address is utilized for criminal activity by those with access to it.

That risk transfer is the entire product. Residential IP space is trusted by fraud engines, rate limiters, geo-restriction checks and login-risk scoring in a way that data-centre space is not. Credential-stuffing runs that would be blocked from a hosting provider’s range succeed when they arrive from a Comcast line in Miami. The same property makes these proxies useful to initial access brokers logging in with credentials pulled from stealer logs, because a session originating from the victim’s own city looks unremarkable to the systems watching for anomalies.

For defenders, the practical takeaways are narrow and old:

  • Treat end-of-life routers and IoT devices as compromised infrastructure rather than retired hardware. They keep routing traffic long after they stop receiving patches.
  • Do not treat a residential ASN as a trust signal on its own. The 2008 panel and the 2025 indictment describe the same product sixteen years apart.
  • Geolocation matching is not authentication. City-level accuracy has been purchasable on the underground since at least 2008.

The wider lesson is about timelines. 5socks.net operated for roughly twenty years. The hypothesis that it was botnet-backed was available to anyone reading the member panel in 2008, and confirmation took until 2025. Attribution and disruption in this ecosystem run on decade-scale clocks, which is worth remembering the next time a service looks too durable to be criminal.

Frequently asked questions

What was 5socks.net?

5socks.net was a proxy-as-a-service platform that sold subscription access to SOCKS proxies running on compromised routers and IoT devices. Its own slogan claimed operation since 2004.

Who ran 5socks.net?

The Department of Justice charged three Russian nationals, Alexey Chertkov, Kirill Morozov and Aleksandr Shishkin, and a Kazakhstani national, Dmitriy Rubtsov, in May 2025. The indictment covers the later years of the service rather than its mid-2000s origins.

Was 5socks.net a botnet?

Yes, according to the U.S. indictment. Prosecutors allege the proxies were older wireless routers infected with malware and reconfigured for third-party access without their owners’ knowledge.

How much did 5socks.net cost?

Court documents put subscriptions between .95 and 0 per month, with more than 7,000 proxies advertised worldwide. Prosecutors estimate the operation earned more than million.

Is 5socks.net still online?

No. The FBI seized 5socks.net and anyproxy.net in May 2025 under Operation Moonlander, and both domains now display law-enforcement seizure notices.

How do I tell if my router is part of a proxy botnet?

Check whether your device still receives vendor firmware updates and replace it if it is end-of-life. Unexplained outbound connections, degraded upstream bandwidth and configuration changes you did not make are the practical warning signs.

What replaced 5socks.net?

Residential proxy services remain widely available on criminal forums, and Black Lotus Labs has documented comparable networks including Faceless and NSOCKS. The seizure removed one supplier, not the market.

Sources and further reading

  • U.S. Department of Justice: Botnet Dismantled in International Operation, Russian and Kazakhstani Administrators Indicted
  • DoJ court documents (Northern District of Oklahoma) and accompanying filing
  • Lumen Black Lotus Labs: Classic rock, hunting a botnet that preys on the old
  • CyberScoop: US seizes Anyproxy, 5socks botnets and indicts alleged administrators
  • The Record: Three Russians, one Kazakhstani charged in takedown of Anyproxy and 5socks botnets
  • Ransomnews threat-group catalogue
  • OSINT investigation walkthrough: tracing criminal infrastructure
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleCodename Morgan: inside Morocco’s Pegasus machine
Dancho Danchev
  • LinkedIn

Dancho Danchev is a Bulgarian threat intelligence researcher who has spent more than two decades tracking cybercrime, malware campaigns, and the infrastructure behind the criminal underground. His research covers botnets, including Koobface, exploit kits, blackhat SEO, scareware, and large-scale domain abuse, with a focus on OSINT work that maps campaigns back to the operators running them. He has published through ZDNet Zero Day, Webroot, GroupSense, and WhoisXML API, and has run his own cybercrime research blog since the early 2000s.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.