Botnet of more than 17 million devices dismantled
Dutch authorities say they took down a botnet spanning more than 17 million devices and 200 servers, after a researcher tipped them off.
Intelligence analysis by GPT-5.4 Mini
Dutch police and the National Cyber Security Center say they dismantled a massive botnet hosted in the Netherlands, with more than 17 million devices and 200 servers involved. The operation may be tied to residential proxy services and past abuse reports.
Police in the Netherlands found a huge bad network of internet-connected devices and turned it off. The network had more than 17 million devices in it, like a giant pile of borrowed phones and computers being used for trouble.
A good way to think about it is a crowd wearing the same disguise. From far away, the bad traffic looks normal, which makes it harder to catch. That can help criminals hide phishing, fake attacks, and other scams.
The article says people can lower the risk by keeping devices updated and not installing apps unless they are truly needed. Old or shady apps can act like an open door for trouble.
Analysis
What happened
Dutch authorities said they dismantled a botnet made up of more than 17 million devices and managed through 200 servers. The action was announced after a security researcher reported the network, and the infrastructure was hosted in the Netherlands.
Police said they seized several botnet servers from a hosting provider for investigation, and the provider took the botnet offline because it was being used for criminal purposes. The article says the network was linked in a separate report to ASOCKS, a Russia-based company that sells residential proxy services, though Ars says it could not independently confirm that linkage.
Why proxy services matter
Residential proxies route traffic through third-party devices, which can make traffic look more like ordinary internet use. The article notes that such services are often used for abuse, including DDoS attacks, command-and-control, phishing, and scraping. A Dutch cyber agency post warned that these proxies can make cybercrime mitigation harder because malicious traffic can resemble normal traffic.
Prior signals and open questions
The story points to earlier research from Human, which said it found evidence linking a botnet called Proxylib to ASOCKS. That report described infected IP addresses and proxy-list data that appeared to connect the two. The article also says 28 Google Play apps had enrolled as many as 190,000 devices into the Russia-headquartered proxy network without user approval.
It remains unclear how the 17 million devices in the dismantled botnet were recruited. The article says devices can be swept up through exploited vulnerabilities, malicious apps, or unclear disclosures buried in app terms or interface text. The practical advice is straightforward: install updates promptly, avoid using unsupported software, research apps before installing them, and remove apps that are no longer needed.
Key points
- Dutch authorities say they dismantled a botnet involving more than 17 million devices and 200 servers.
- The infrastructure was hosted in the Netherlands and was taken offline after a security researcher reported it.
- The botnet was reported as linked to ASOCKS, a Russia-based residential proxy service, though Ars could not independently confirm that link.
- Residential proxies can help criminals hide where traffic comes from and make abuse harder to block.
- The article advises timely updates, avoiding unsupported software, and being careful about which apps to install.



