NETHERLANDS — Dutch authorities dismantled a botnet comprising more than 17 million devices managed by 200 servers in a joint operation conducted by the National Police and the National Cyber Security Center (NCSC). The host infrastructure of the botnet was located in the Netherlands, prompting local law enforcement to act on intelligence gathered in coordination with the NCSC.
The botnet was linked to ASOCKS, a Russia-based company that provides residential proxy services, according to a report by NL Times. The takedown followed the seizure of several botnet servers from a Dutch hosting provider, which subsequently took the network offline after determining it was being used for criminal purposes, the NCSC said. Authorities acted after a security researcher reported the botnet’s existence.
The seized servers controlled computers, tablets, and smartphones to carry out cyberattacks, officials said. ASOCKS offers residential, corporate, and mobile proxies through monthly subscriptions ranging from $5 to $15, advertising access to 7 million IP addresses across 150 locations and claiming 100,000 clients. Residential proxy services like ASOCKS route internet traffic through third-party devices, enabling users to mask their identities or bypass geographic restrictions.
Such services are frequently exploited for illicit activities, including distributed denial-of-service (DDoS) attacks, phishing campaigns, botnet command-and-control operations, and unauthorized web scraping. In 2024, security firm Human identified connections between a botnet called Proxylib and ASOCKS, citing evidence such as infected IP addresses returned by an ASOCKS proxy-list endpoint and traffic from an infected test device routed through asocks[.]com.
Twenty-eight apps on Google Play reportedly enrolled up to 190,000 devices into the ASOCKS proxy network without users’ informed consent. Some apps disclosed their proxy functionality in fine or obscured print, while others provided clearer notices. It remains unclear how the 17 million devices in the dismantled botnet were initially compromised, though infection commonly occurs via software vulnerabilities or malicious applications.
The NCSC published a post on Wednesday titled “Residential proxies and their major impact on digital security in the Netherlands,” warning that such services complicate cybercrime mitigation by enabling anonymity and circumvention of geographic blocks. Questions sent to ASOCKS received no response. The NCSC’s actions indicate that device owners whose systems were absorbed into the botnet were unaware their devices supported cybercriminal operations.
forum Comments (0)
No comments yet. Be the first to comment.