Incident Response
Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices
Cyber RTMay 31, 20263 min read

Dutch authorities dismantled a botnet comprising over 17 million infected devices, used for cyber attacks. The botnet's infrastructure included over 200 servers in the Netherlands, some of which were seized by police. The botnet, reportedly linked to Asocks, exploited devices through proxyware. To mitigate such threats, users are advised to update systems, secure devices, use strong passwords, and enable two-factor authentication.
Dutch authorities have successfully dismantled a massive botnet that had compromised millions of devices worldwide. This network included a variety of devices such as computers, tablets, smartphones, and Internet of Things (IoT) devices, which were all hijacked to execute malicious cyber activities. The operation was a collaborative effort between the Dutch Politie and the National Cyber Security Center (NCSC), highlighting the scale and severity of the threat posed by such botnets.
The botnet was composed of at least 17 million infected devices, with its backend infrastructure supported by more than 200 servers located in the Netherlands. These servers played a crucial role in the botnet's operations, facilitating the coordination and execution of cyber attacks. The authorities were able to seize a portion of these servers, which were hosted by a provider that unknowingly supported the botnet's infrastructure, leading to its eventual shutdown.
While the specific name of the botnet was not disclosed by the authorities, reports from local media, such as the NL Times, identified the implicated service as Asocks. Asocks is known for offering residential proxy services, which can be used for both legitimate and illicit purposes. Earlier in April 2024, HUMAN's Satori Threat Intelligence team had uncovered a campaign named PROXYLIB, which involved Android devices infected with proxyware from LumiApps and Asocks.
Asocks' platform markets various proxy services, including corporate, residential, and mobile proxies, available through monthly subscriptions. These services are priced between $5 and $15, with discounts offered for bulk purchases. While residential proxies can provide legitimate privacy benefits and access to geographically-restricted content, they also attract malicious actors who exploit compromised devices to route harmful traffic and conduct cyber attacks.
The NCSC emphasized the vulnerability of devices to becoming part of a botnet when they are accessible to cybercriminals. Once attackers gain access, they can install malware that allows them to control the device remotely, integrating it into a network used for illegal activities. This highlights the importance of securing devices to prevent them from being hijacked.
To mitigate the risks associated with botnet malware, the NCSC advises several precautionary measures. These include keeping operating systems updated, maintaining visibility of edge devices like routers, using strong and unique passwords, enabling two-factor authentication, installing applications only from trusted sources, changing default passwords, and securing Wi-Fi networks with WPA2 or WPA3 encryption.
The takedown of this botnet underscores the ongoing battle against cybercrime and the importance of international cooperation in tackling such threats. It also serves as a reminder of the critical need for individuals and organizations to adopt robust cybersecurity practices to protect their devices from being exploited by malicious actors.