discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Botnet of more than 17 million devices dismantled

Dutch authorities say they took down a botnet spanning more than 17 million devices and 200 servers, after a researcher tipped them off.

By Dan Goodin·May 29·arstechnica.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Dutch police and the National Cyber Security Center say they dismantled a massive botnet hosted in the Netherlands, with more than 17 million devices and 200 servers involved. The operation may be tied to residential proxy services and past abuse reports.

Why it matters

A botnet this large can be used to hide attacks, run phishing, scrape sites, and make abuse harder to trace. The takedown highlights how proxy networks and compromised devices can be used together to support criminal infrastructure.

Police in the Netherlands found a huge bad network of internet-connected devices and turned it off. The network had more than 17 million devices in it, like a giant pile of borrowed phones and computers being used for trouble.

A good way to think about it is a crowd wearing the same disguise. From far away, the bad traffic looks normal, which makes it harder to catch. That can help criminals hide phishing, fake attacks, and other scams.

The article says people can lower the risk by keeping devices updated and not installing apps unless they are truly needed. Old or shady apps can act like an open door for trouble.

Analysis

What happened

Dutch authorities said they dismantled a botnet made up of more than 17 million devices and managed through 200 servers. The action was announced after a security researcher reported the network, and the infrastructure was hosted in the Netherlands.

Police said they seized several botnet servers from a hosting provider for investigation, and the provider took the botnet offline because it was being used for criminal purposes. The article says the network was linked in a separate report to ASOCKS, a Russia-based company that sells residential proxy services, though Ars says it could not independently confirm that linkage.

Why proxy services matter

Residential proxies route traffic through third-party devices, which can make traffic look more like ordinary internet use. The article notes that such services are often used for abuse, including DDoS attacks, command-and-control, phishing, and scraping. A Dutch cyber agency post warned that these proxies can make cybercrime mitigation harder because malicious traffic can resemble normal traffic.

Prior signals and open questions

The story points to earlier research from Human, which said it found evidence linking a botnet called Proxylib to ASOCKS. That report described infected IP addresses and proxy-list data that appeared to connect the two. The article also says 28 Google Play apps had enrolled as many as 190,000 devices into the Russia-headquartered proxy network without user approval.

It remains unclear how the 17 million devices in the dismantled botnet were recruited. The article says devices can be swept up through exploited vulnerabilities, malicious apps, or unclear disclosures buried in app terms or interface text. The practical advice is straightforward: install updates promptly, avoid using unsupported software, research apps before installing them, and remove apps that are no longer needed.

Key points

  • Dutch authorities say they dismantled a botnet involving more than 17 million devices and 200 servers.
  • The infrastructure was hosted in the Netherlands and was taken offline after a security researcher reported it.
  • The botnet was reported as linked to ASOCKS, a Russia-based residential proxy service, though Ars could not independently confirm that link.
  • Residential proxies can help criminals hide where traffic comes from and make abuse harder to block.
  • The article advises timely updates, avoiding unsupported software, and being careful about which apps to install.

Originally reported at

arstechnica.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritytechsocietyglobal-news

Author

Dan Goodin

Intelligence analysis by

GPT-5.4 Mini

Published

May 29, 2026

Source

arstechnica.com

Share

Topics

securitytechsocietyglobal-news

Related

More from this desk

Jul 29·techcrunch.com

Hint, a new AI startup co-founded by Martha Stewart, offers an AI assistant for homeowners

Martha Stewart co-founded Hint, an AI app for homeowners to manage tasks, energy, and home maintenance. The app uses AI to provide personalized home maintenance schedules and offers an AI chatbot for questions.

Jul 29·scmp.com

Why US-led alliance might struggle to rein in Beijing’s growing 6G influence

The US is building a 24-country 6G alliance to counter Beijing's growing influence in the next-generation technology. Analysts say Washington's efforts face short-term challenges due to China's tech prowess.

Jul 29·spectrum.ieee.org

Negotiating Your Salary Is About More Than Money

Negotiating your salary is not ungrateful or greedy, but rather a business decision that can benefit both you and your employer. It's essential to understand that the first offer is rarely the ceiling, and companies often extend a reasonable number with the hope that you'…

Jul 29·techcrunch.com

Encore AI raises $30M to build AI agents that learn from customer calls

Encore AI, a startup that studies companies' customer interactions to train and deploy AI voice agents, has raised $30 million in a Series A round led by Team8. The company's platform analyzes conversations between a company's employees and customers to identify successfu…