5socks.net sold access to compromised residential IP addresses for more than twenty years before the FBI and the Dutch National Police seized the domain in May 2025. Four men, three Russian nationals and one Kazakhstani, were indicted for running it alongside Anyproxy.net, a business the U.S. Department of Justice says took in more than $46 million. This is where the service came from, and how a question I asked in 2010 finally got answered.
Who was behind 5socks.net?
The service came out of the Russian hacking scene of the mid 2000s, not out of a commercial proxy business.
Historical domain registration records for 5socks.net, and the contact form on the site itself, list a Russian individual, Vladimir Belyankin. Those records establish who registered the domain in the mid 2000s. They do not establish who operated the service in the years that followed, and Belyankin is not among the four people charged by the Department of Justice in 2025.
The more productive pivot is the address used in that registration record, [email protected]. Whoever registered 5socks.net used an email address belonging to another project of theirs, the Gh0st Security Team, whose site sat at gst.void.ru and which public records show was active in 2005. This is a standard registrant-to-project pivot, the same technique covered in our domain and subdomain reconnaissance guide, and in this case it ties a commercial proxy service directly to a named hacking crew.

Although for today’s hacking groups jumping into a commercial cybercrime service offering might look unremarkable, back then for a Russian hacking group to launch one was innovative. The underground now runs on subscriptions, tiered pricing and support channels. In 2005 that model was still being invented, and 5socks.net was one of the places it was invented.
What 5socks.net actually sold
5socks.net sold timed access to a rotating pool of SOCKS proxies running on other people’s internet connections.
Back in the day when I was doing cybercrime research on my own in 2010, the service stood as a cornerstone to some, while the majority of others were presuming that it was used primarily for anonymization. It was one of the most heavily advertised offerings of its kind on prominent Russian cybercrime forums.
Among the few things that personally impressed me when I originally analyzed and profiled the service was the level and degree of geolocation applied to the available IPs, which was relatively advanced and sophisticated for its time. The member panel did not simply list addresses. It listed country, state, city, connection type, uptime, time since last check and response speed, and it let a buyer sort the inventory by any of them.

The hostnames in that listing are the giveaway. Comcast, Charter, RoadRunner, SBC and Pacbell reverse-DNS entries in Concord, Orange Park, Palm Desert, Houston, Albany, Monterey, Staten Island, Bucyrus, Opelousas, Miami and Fresno. Those are ordinary domestic broadband lines in American towns, not data-centre ranges.
The question nobody could answer in 2010
One question logically emerged back then. How is it possible that a Russia based proxy-as-a-service would acquire and have access to thousands of available U.S. based IP addresses?
There were only two answers. Either the users of those connections were knowingly participating with their IPs and bandwidth, or the service was obtaining access by other means, for instance using botnets.
The consent explanation never held up well. Nobody was running a paid opt-in bandwidth programme in Concord, North Carolina in 2008 that would have terminated on a Russian-language forum’s proxy panel, and the buyer-side pricing was far too low to fund one. The botnet explanation fit the evidence better, but in 2010 it was a reading of the data, not a finding. Without visibility into the infected devices themselves, it stayed a hypothesis for fifteen years.
What Operation Moonlander found
The May 2025 takedown answered it. On 9 May 2025 the Department of Justice unsealed a domain seizure warrant alongside an indictment charging four foreign nationals, announced by U.S. Attorney Clint Johnson for the Northern District of Oklahoma.
Alexey Viktorovich Chertkov, Kirill Vladimirovich Morozov and Aleksandr Aleksandrovich Shishkin, all Russian nationals, and Dmitriy Rubtsov, a Kazakhstani national, were charged with conspiracy and damage to protected computers. Chertkov and Rubtsov face an additional count of false registration of a domain name, on the allegation that they falsely identified themselves when registering and using 5socks.net and anyproxy.net. All four reside outside the United States.
The mechanism described in the indictment is the botnet answer. According to the DoJ, a botnet was created by infecting older-model wireless internet routers worldwide, including in the United States, using malware, without the owners’ knowledge. That malware allowed the routers to be reconfigured so unauthorized third parties could be granted access, and the devices were then made available for sale as proxy servers on the two websites. Both domains were managed by a company headquartered in Virginia and hosted on servers worldwide.
The commercial detail matches the 2008 panel closely. Court documents put more than 7,000 proxies advertised for sale worldwide, on subscriptions ranging from $9.95 to $110 per month. The site’s own slogan, “Working since 2004!”, is what prosecutors cite for the twenty-year runtime. The defendants are believed to have amassed more than $46 million from selling access to the infected routers.
The operation ran as the FBI plus the Dutch National Police, the Netherlands Public Prosecution Service and the Royal Thai Police, with Lumen Technologies’ Black Lotus Labs providing network visibility. Both domains now serve seizure notices.
What the infected fleet actually looked like
Black Lotus Labs tracked the network for over a year before the takedown, and its findings fill in what the criminal panel never showed.
The team observed a weekly average of around 1,000 unique bots contacting command-and-control infrastructure located in Turkey. Over half the victims were in the United States, with Canada and Ecuador next. The device population was IoT and end-of-life hardware, and Lumen’s assessment was that the operators were not burning zero-days or one-days on it. They relied on exploits that had been public for years, which is exactly what a focus on unpatched and end-of-life devices implies. Black Lotus Labs deliberately withheld malware detail on the grounds that the devices are easy to re-exploit by others.
That is the shape of a durable business, not a spectacular one. A thousand concurrent bots is small next to the botnets that make headlines. It was enough, because what the buyers were paying for was never volume. It was residential legitimacy.
Why this still matters in 2026
The 5socks.net model did not die with the seizure, because the demand behind it did not.
With the cybercrime ecosystem currently overpopulated with similar commercial propositions, the popularity of this one service is only scratching the surface of a bigger problem, where today, just like a decade ago, cybercriminals can truly forward the risk for their malicious and fraudulent online actions to a third-party user who is unsuspecting and unknowingly participating in a botnet, and whose home or office based IP address is utilized for criminal activity by those with access to it.
That risk transfer is the entire product. Residential IP space is trusted by fraud engines, rate limiters, geo-restriction checks and login-risk scoring in a way that data-centre space is not. Credential-stuffing runs that would be blocked from a hosting provider’s range succeed when they arrive from a Comcast line in Miami. The same property makes these proxies useful to initial access brokers logging in with credentials pulled from stealer logs, because a session originating from the victim’s own city looks unremarkable to the systems watching for anomalies.
For defenders, the practical takeaways are narrow and old:
- Treat end-of-life routers and IoT devices as compromised infrastructure rather than retired hardware. They keep routing traffic long after they stop receiving patches.
- Do not treat a residential ASN as a trust signal on its own. The 2008 panel and the 2025 indictment describe the same product sixteen years apart.
- Geolocation matching is not authentication. City-level accuracy has been purchasable on the underground since at least 2008.
The wider lesson is about timelines. 5socks.net operated for roughly twenty years. The hypothesis that it was botnet-backed was available to anyone reading the member panel in 2008, and confirmation took until 2025. Attribution and disruption in this ecosystem run on decade-scale clocks, which is worth remembering the next time a service looks too durable to be criminal.
Frequently asked questions
What was 5socks.net?
5socks.net was a proxy-as-a-service platform that sold subscription access to SOCKS proxies running on compromised routers and IoT devices. Its own slogan claimed operation since 2004.
Who ran 5socks.net?
The Department of Justice charged three Russian nationals, Alexey Chertkov, Kirill Morozov and Aleksandr Shishkin, and a Kazakhstani national, Dmitriy Rubtsov, in May 2025. The indictment covers the later years of the service rather than its mid-2000s origins.
Was 5socks.net a botnet?
Yes, according to the U.S. indictment. Prosecutors allege the proxies were older wireless routers infected with malware and reconfigured for third-party access without their owners’ knowledge.
How much did 5socks.net cost?
Court documents put subscriptions between .95 and 0 per month, with more than 7,000 proxies advertised worldwide. Prosecutors estimate the operation earned more than million.
Is 5socks.net still online?
No. The FBI seized 5socks.net and anyproxy.net in May 2025 under Operation Moonlander, and both domains now display law-enforcement seizure notices.
How do I tell if my router is part of a proxy botnet?
Check whether your device still receives vendor firmware updates and replace it if it is end-of-life. Unexplained outbound connections, degraded upstream bandwidth and configuration changes you did not make are the practical warning signs.
What replaced 5socks.net?
Residential proxy services remain widely available on criminal forums, and Black Lotus Labs has documented comparable networks including Faceless and NSOCKS. The seizure removed one supplier, not the market.
Sources and further reading
- U.S. Department of Justice: Botnet Dismantled in International Operation, Russian and Kazakhstani Administrators Indicted
- DoJ court documents (Northern District of Oklahoma) and accompanying filing
- Lumen Black Lotus Labs: Classic rock, hunting a botnet that preys on the old
- CyberScoop: US seizes Anyproxy, 5socks botnets and indicts alleged administrators
- The Record: Three Russians, one Kazakhstani charged in takedown of Anyproxy and 5socks botnets
- Ransomnews threat-group catalogue
- OSINT investigation walkthrough: tracing criminal infrastructure
