Episode

Behind the scenes of the Socksescort takedown

Podcast
Safe Mode Podcast
Published
Mar 19, 2026
Duration seconds
2094
Processing state
not_requested
Canonical source
https://soundcloud.com/podcast-defensescoop-com/behind-the-scenes-of-the
Audio
https://feeds.soundcloud.com/stream/2286984320-podcast-defensescoop-com-behind-the-scenes-of-the.mp3
JSON
/v1/public/podcasts/safe-mode-podcast-6421323/episodes/behind-the-scenes-of-the-socksescort-takedown
Markdown
/podcast/safe-mode-podcast-6421323/behind-the-scenes-of-the-socksescort-takedown.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/safe-mode-podcast-6421323/episodes/behind-the-scenes-of-the-socksescort-takedown/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/safe-mode-podcast-6421323/behind-the-scenes-of-the-socksescort-takedown.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this episode, we sit down with Chris Formosa to break down the Socksescort disruption—a proxy botnet powered by AVRecon that compromised edge devices at scale. Chris walks us through why the operation was so dangerous, how investigators tracked its command-and-control infrastructure, and what changed between the 2023 disclosure and the eventual takedown in coordination with the Department of Justice. We also dig into why edge devices remain prime targets, where most organizations still have visibility gaps, and what the next evolution of this threat could be. In our reporter chat, Greg Otto and Tim Starks break down DarkSword, a iOS exploit kit that could impact hundreds of millions of people.