Cybercrime

Dutch Police Dismantle Massive 17-Million-Device Botnet

Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.

Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.

Dutch police say they have disrupted a massive botnet consisting of 17 million infected computers, smartphones, and tablets.

According to the authorities, the botnet was discovered after a security researcher reported it to the Netherlands’ National Cyber Security Centre (NCSC-NL).

During their investigation into the botnet, the authorities identified 200 servers used to control infected devices and launch cyberattacks.

As part of the takedown efforts, several servers associated with the botnet were seized from a hosting provider in the Netherlands, and the provider took down the entire network for being used for illicit activities, the police say.

“Criminals can remotely control the devices, often without the owner noticing. Botnets are used for cyberattacks, sending spam and phishing emails, online fraud, and disrupting websites by sending large amounts of internet traffic simultaneously,” the Dutch police said.

The Dutch authorities did not name the hosting provider, nor the botnet, but local media reports that the takedown operation targeted Asocks, a company that provides residential proxy services.

Advertisement. Scroll to continue reading.

The botnet consisted of consumer devices reportedly infected with malware, allowing cybercriminals to control them remotely and use them to route malicious traffic as part of large-scale cyberattacks.

Users are advised to keep their devices updated, keep track of edge devices connected to their networks, use unique, strong passwords and multi-factor authentication (MFA), install apps only from trusted sources, secure their Wi-Fi networks, and use anti-malware solutions on their devices.

The disruption follows the takedown of Aisuru, Kimwolf, and other botnets used to launch distributed denial-of-service (DDoS) attacks. Kimwolf, believed to have infected over 2 million devices, was also propagating through residential proxy networks.

Related: GlassWorm Botnet Disrupted

Related: Canadian Man Arrested for Operating Kimwolf Botnet

Related: Mirai Botnet Targets Flaw in Discontinued D-Link Routers

Related: Evasive Masjesu DDoS Botnet Targets IoT Devices

Related Content

IoT Security

Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.

Malware & Threats

Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.

Malware & Threats

Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware.

Cybercrime

Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges.

Malware & Threats

The exploitation of the command injection vulnerability started one year after public disclosure and PoC exploit code publication.

Malware & Threats

Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities.

Cybercrime

Ilya Angelov was a member of the cybercrime group tracked as TA-551, Shathak, Gold Cabin, Monster Libra, and ATK236.

Cybercrime

The lesser-known JackSkid and Mossad botnets have also been targeted in the operation.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version