Dutch law enforcement and the Netherlands’ National Cyber Security Center (NCSC) dismantle a large botnet involving more than 17 million infected devices, including computers, smartphones, and tablets. Authorities report that the botnet is managed through command-and-control infrastructure operating from the Netherlands, with activity distributed across roughly 200 servers. The operation follows reporting by a security researcher to authorities. After receiving the information, police seize several botnet servers from a hosting provider for investigation, and the hosting provider takes the botnet offline because it is used for criminal purposes.

Multiple reports describe the botnet as being connected to a residential proxy network used to conceal locations or identities. Such proxy services can be used in cybercrime, including facilitating additional malicious activity. One report further says the botnet is linked to ASOCKS, described as a Russia-based provider of residential proxy services. Authorities do not publicly detail, in the available coverage, how the devices were enrolled or the full scope of uses beyond proxy-related criminal activity.