Dutch govt disrupts malware botnet with 17 million infected devices
Dutch authorities say they took offline a botnet made up of at least 17 million infected devices and seized more than 200 supporting servers.
Intelligence analysis by GPT-5.4 Mini

Dutch police and the NCSC say they disrupted a large botnet hosted in the Netherlands, with infected computers, tablets, and phones used for cyberattacks. Local reporting linked the infrastructure to Asocks, but the authorities did not name the botnet.
A huge group of devices got tricked into following secret commands from criminals. Dutch officials say they shut down the computers that were giving those commands.
Think of it like a school bus driver being replaced by a thief. The bus is still full of kids, but the thief is the one steering it around. Cutting off the thief helps stop the chaos.
The bad part is that many of the devices may not even know they were being used. The good part is that police and cyber experts found the control center and turned it off.
Analysis
What happened
Dutch authorities say they disrupted a botnet that had infected at least 17 million devices. The National Cyber Security Centre said the infrastructure used more than 200 servers in the Netherlands, and police worked with the hosting provider to take the network offline.
What the botnet was used for
According to the article, the seized servers controlled computers, tablets, and smartphones and were used for cyberattacks. Botnets like this are commonly used for distributed denial-of-service attacks, traffic proxying, and other forms of abuse.
The suspected link
The authorities did not name the botnet, but local media tied it to Asocks, a service that markets itself as a universal proxy platform. The article says Asocks advertises millions of IP addresses, many locations, and paying clients, with subscriptions starting in the single-digit dollar range and discounts for larger purchases.
Why this matters
The NCSC's statement suggests the infected device owners were not knowingly helping criminal operators. That distinction matters: a proxy service can sound legitimate on paper, but if the underlying devices are compromised, the infrastructure becomes part of a criminal operation. The action also shows a practical defense model: identify the hosting layer, seize or isolate the servers, and remove the botnet's control channel rather than waiting for every infected device to be cleaned first.
BleepingComputer says it contacted Asocks for comment and had not received a response by publication time.
Key points
- Dutch authorities say they took a botnet offline after investigating it with the NCSC.
- The botnet was said to include at least 17 million infected devices.
- More than 200 servers in the Netherlands were allegedly used to host the infrastructure.
- Local reporting linked the operation to Asocks, but authorities did not name it.
- The article says the hosting provider helped take the botnet offline for investigation purposes.



