Global cyber raid shuts down massive 17 million-device botnet network

Global cyber raid shuts down massive 17 million-device botnet network

Global cyber raid shuts down massive 17 million-device botnet network

https://interestingengineering.com/culture/17-million-device-botnet-taken-offline-cybersecurity

Publish Date: 2026-05-29 16:20:00

Source Domain: interestingengineering.com

Dutch authorities dismantled a massive botnet that controlled more than 17 million infected devices in one of the largest cybercrime disruptions in recent years.

The operation involved the Dutch National Police and the National Cyber Security Centre (NCSC). Investigators identified around 200 servers that managed the network’s infrastructure. Officials said the servers operated from hosting facilities inside the Netherlands.

The investigation started after a cybersecurity researcher alerted the NCSC about suspicious activity tied to a sprawling proxy network. Authorities traced the infrastructure and launched a joint probe with law enforcement agencies.

Millions of infected devices

Investigators found that the botnet controlled at least 17 million compromised devices. The infected hardware included computers, smartphones, tablets, routers, and smart home products connected to the internet.

Police later seized several servers connected to the network. Hosting providers also disabled parts of the infrastructure after authorities confirmed the systems supported criminal activity.

Officials said cybercriminals used the botnet to conduct attacks and conceal online operations. According to Dutch authorities, the network supported phishing campaigns, spam distribution, and distributed denial-of-service attacks targeting online services.

The Dutch newspaper NL Times linked the network to ASOCKS, a Russia-based residential proxy provider. Residential proxy services route internet traffic through third-party consumer devices. Users often rely on these services to disguise their location or identity online.

Residential proxies under scrutiny

Cybersecurity experts have increasingly warned about the misuse of residential proxy networks. These systems can blend malicious traffic with legitimate internet activity, making attacks significantly harder to detect.

In a separate advisory, the NCSC warned that cybercriminals use residential proxies…

Source