Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
Dutch authorities took down a botnet tied to at least 17 million infected devices and more than 200 backend servers in the Netherlands.
Intelligence analysis by GPT-5.4 Mini
Dutch police and the NCSC say they disrupted a large botnet that used infected computers, phones, tablets, and IoT devices for criminal activity. The operation reportedly involved servers in the Netherlands and may have been linked to a residential proxy service called Asocks.
Police in the Netherlands said they broke up a huge bad network of hacked devices. The network used phones, computers, tablets, and smart gadgets like tiny workers doing secret dirty jobs.
Think of it like one thief using millions of toy walkie-talkies to send orders. The devices were being controlled from the outside, and some servers in the Netherlands helped run it.
The lesson is simple: keep gadgets updated, use strong passwords, and turn on extra lock steps when possible. That makes it harder for bad actors to take over devices in the first place.
Analysis
What happened
Dutch authorities said they dismantled a botnet that had enslaved millions of infected devices, including computers, tablets, smartphones, and IoT gear. The Dutch Politie and the National Cyber Security Center said the network included at least 17 million infected devices.
More than 200 servers in the Netherlands were being used as backend infrastructure for the service. According to the NCSC, police seized a subset of those servers from a hosting provider that had been supplying the infrastructure. The provider then took the botnet offline after it was used for criminal purposes.
What the article says about attribution
The botnet name was not explicitly stated in the Dutch authorities' announcement. However, NL Times reported that the service was Asocks, a company that sells residential proxies. The article also notes that HUMAN's Satori Threat Intelligence team had previously identified a 2024 campaign, called PROXYLIB, involving infected Android devices with proxyware from LumiApps and Asocks.
Why it matters
The story highlights the overlap between botnets and the residential proxy market. Residential proxies can have legitimate uses, but the article says the ecosystem is also used by bad actors who buy access to compromised devices to route malicious traffic.
The NCSC warned that devices can become part of a botnet once attackers gain access and install malware that enables remote control. The article closes with basic defense advice: keep systems updated, watch edge devices like routers, use strong passwords, enable two-factor authentication, install apps from trusted sources, change default passwords, and secure Wi-Fi with WPA2 or WPA3.
Key points
- Dutch authorities said they dismantled a botnet tied to at least 17 million infected devices.
- More than 200 servers in the Netherlands were used as backend infrastructure.
- Police seized some servers from a hosting provider, which then took the botnet offline.
- NL Times reported the service may have been Asocks, a residential proxy provider.
- The article warns that compromised devices can be used for cybercriminal activity and recommends basic hardening steps.



