Dutch Authorities Take Down Botnet That Infected an Estimated 17 Million Devices
Dutch law enforcement, together with the National Cyber Security Center (NCSC), announced the disruption of a sprawling botnet that had enrolled millions of devices-ranging from desktop and laptop computers to tablets, smartphones and other Internet of Things (IoT) hardware-into a criminalized network used for cyberattacks.
According to statements from the NCSC and the Politie, investigators believe the botnet included at least 17 million compromised endpoints. More than 200 servers hosted in the Netherlands served as the platform’s backend, and police were able to seize a portion of those machines from a hosting firm that supplied the infrastructure. That provider reportedly took the service offline after authorities determined it was being used for illegal activity.
The official announcements did not name the botnet, but Dutch media outlet NL Times identified the infrastructure as linked to Asocks, a company that markets residential proxy services. In related research published in April 2024, HUMAN’s Satori Threat Intelligence team described a campaign it labeled PROXYLIB, which involved Android devices infected with proxyware attributed to LumiApps and Asocks.
Information from Asocks’ own site indicates the company offers corporate, residential and mobile proxy subscriptions priced between $5 and $15 per month, with bulk discounts of roughly 5%-15% for orders covering 10 to 100 proxies. While residential proxies can be used legitimately-for example, to access geo-restricted content-the sector is also opaque and has attracted misuse. Some providers sell access to networks made up of compromised devices, allowing buyers to channel harmful traffic and mount attacks through otherwise unsuspecting hardware.
Explaining how devices become enlisted in such networks, the NCSC noted that “devices can become part of a botnet when they are accessible to malicious actors. After gaining access, attackers can install malware that allows the device to be controlled remotely. This enables the device to become part of a network used for cybercriminal activities.”
To reduce the risk of devices being co-opted into botnets, authorities and security experts recommend several defensive measures: keep operating systems and firmware current, maintain visibility into edge equipment such as routers, use strong and unique passwords, enable two-factor authentication wherever available, only install applications from trusted sources, change manufacturer default credentials, and protect wireless networks with WPA2 or WPA3 encryption.