Dutch Police and NCSC Seize 200 Servers to Knock Out 17-Million-Device Proxy Botnet

Dutch authorities dismantled a 17-million-device botnet by seizing over 200 servers in the Netherlands, disrupting a residential proxy network linked to Asocks and used for cybercrime. The joint police-NCSC operation followed a researcher tip and highlights growing threats from compromised consumer devices.
Dutch Police and NCSC Seize 200 Servers to Knock Out 17-Million-Device Proxy Botnet
Written by Elizabeth Morrison

Dutch police and the National Cyber Security Centre (NCSC) dismantled a botnet spanning at least 17 million compromised devices. The joint operation targeted infrastructure hosted on more than 200 servers located inside the Netherlands.

The takedown followed a tip from a security researcher who alerted the NCSC. Authorities traced the command infrastructure to a Dutch hosting provider. Police from the cybercrime unit in The Hague seized several servers for investigation. The provider then disconnected the remaining systems after confirming their use in criminal activity.

Devices in the network included computers, tablets, smartphones, routers, and IoT products such as security cameras. Owners had no idea their hardware routed malicious traffic. The NCSC stated in its announcement that the botnet consisted of at least 17 million infected devices and that the 200 servers used to host the infrastructure were located in the Netherlands. NCSC announcement

Local reporting identified the service as Asocks, a Russia-based residential proxy provider. Asocks markets itself as offering corporate, residential, and mobile proxies with claimed access to millions of IP addresses across 150 locations and roughly 100,000 clients. Subscription prices range from $5 to $15 per month, with discounts for bulk purchases. NL Times

Residential proxy services let customers route traffic through third-party devices to mask origins or bypass geographic restrictions. Legitimate uses exist. The same networks also support phishing campaigns, DDoS attacks, credential stuffing, and content scraping when devices are compromised without consent.

The NCSC had published a related expert blog the day before the announcement. It described residential proxies as a growing concern because they blend malicious traffic with ordinary consumer connections, complicating detection and mitigation. The post was later updated with a link to the botnet operation details. Ars Technica

Scale and prior links to Asocks

Earlier investigations tied Asocks infrastructure to campaigns that enrolled Android devices without full user awareness. In 2024, HUMAN’s Satori Threat Intelligence team documented the PROXYLIB operation. It involved 28 apps on Google Play that turned phones into proxy nodes, potentially affecting up to 190,000 devices. Some IP addresses and ports matched endpoints returned by Asocks proxy lists. The Hacker News

The current disruption stands out for its size. Most public botnet takedowns involve far fewer nodes. Here, a single action removed control points for millions of devices spread across consumer hardware worldwide. The servers sat in the Netherlands, giving Dutch authorities jurisdiction over the backend even though the infected endpoints were global.

BleepingComputer noted that authorities did not publicly name the service in their statements. Multiple outlets connected the dots through the hosting details and timing. Asocks did not respond to requests for comment from several publications. BleepingComputer

Why residential proxies attract criminals

Attackers favor residential and mobile IPs because they appear as normal user traffic. Corporate or datacenter ranges trigger more blocks. When malware silently converts home routers or phones into exit nodes, the resulting IPs carry the reputation of ordinary households. This makes it harder for banks, e-commerce sites, and security tools to distinguish legitimate sessions from fraud.

The NCSC described the infection path in plain terms. Devices become part of a botnet when accessible to malicious actors. Attackers then install remote-control malware. Owners rarely notice because the malware often runs with low resource use and avoids obvious symptoms. The agency listed standard defenses: keep systems and routers patched, use strong unique passwords with two-factor authentication, install apps only from trusted sources, secure Wi-Fi with WPA2 or WPA3, and monitor connected devices.

Similar operations have targeted other proxy services in recent months. Risky Business highlighted that Asocks joins a list that includes SocksEscort, IPIDEA, and others disrupted by law enforcement. The pattern shows authorities increasingly focusing on the hosting and control layers rather than chasing individual infected devices. Risky Business

The Netherlands has become a notable location for these actions. Strong hosting regulations, active cybercrime units, and close coordination between police and the NCSC enable rapid response once infrastructure is identified domestically. The 200 servers represented a concentrated target that yielded outsized impact.

One immediate effect is the sudden loss of those IPs for paying customers of the proxy service. Criminal users who relied on the network for anonymity must find replacements. Some may shift to other providers that operate similar covert node pools. Others may face higher costs or reduced availability.

Longer term, the operation underscores the tension between commercial proxy offerings and device security. Many proxy services claim their nodes come from voluntary participants who install client software in exchange for payment. When law enforcement seizes servers and providers pull the plug, it signals that at least some portion of the network involved non-consensual enrollment through malware.

Security researchers continue to track how proxy botnets evolve. Earlier Android campaigns showed apps that disclosed proxy functionality in fine print or buried settings. Future variants may use more sophisticated social engineering or exploit supply-chain weaknesses in consumer IoT firmware.

For organizations, the takedown removes one source of noisy residential proxy traffic. Fraud teams that rely on IP reputation scoring may see temporary improvement in signal quality from affected ranges. The relief will be partial. New proxy networks emerge quickly, and the underlying problem of poorly secured edge devices persists.

Consumers can reduce their exposure with basic steps already outlined by the NCSC. Change default router and device passwords immediately. Apply firmware updates when available. Disable remote management features unless required. Review installed apps and remove anything unnecessary. These measures limit the chance that a device joins the next large botnet.

The Dutch operation demonstrates what coordinated national action can achieve against large-scale proxy infrastructure. It also illustrates the limits. The 17 million devices represent only those tied to the seized servers. Many more compromised systems likely remain active under different control structures. Sustained pressure on hosting providers and repeated disruptions will remain necessary to keep the problem in check.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us