Threats · 105 days ago
The hard part is not taking a botnet offline. It is that residential proxy layers let abuse blend into normal consumer traffic, so IP reputation and geo-blocking miss the real source of the attack. When the source looks like a home or mobile user, standard filtering loses its edge.
Dutch police and the NCSC seized more than 200 servers in the Netherlands and took down a botnet tied to at least 17 million infected devices. Reporting linked the infrastructure to ASOCKS, a commercial residential and mobile proxy service used for DDoS, fraud, scraping, and other abuse.
The devices behind that traffic still exist, and the same model can be rebuilt elsewhere. For defenders who trust source IPs too much, the bigger problem is the proxy market itself, which can turn ordinary-looking addresses into cover for large-scale malicious traffic.
6 sources covering this story
Dutch Police Dismantle Massive 17-Million-Device Botnet
Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
Dutch authorities dismantled a 17 million-device botnet backed by 200+ servers, disrupting infrastructure used for cybercrime.
Botnet of more than 17 million devices dismantled
The botnet was reportedly tied to a Russia-based residential proxy network.
Dutch cops wrest 17M devices from mystery botnet's clutches
Hosting provider pulled the plug after police traced 200 servers to the Netherlands
Dutch police disrupts botnet composed of 17 million devices - Help Net Security
200 servers controlling a botnet of 17 million devices have been taken down, th Dutch National Police announced on Thursday.
Dutch govt disrupts malware botnet with 17 million infected devices
Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation.
Part of the PlainSec briefing for 2026-06-01