A huge botnet got shut down. Dutch police and the National Cyber Security Center (NCSC) took down a network of over 17 million devices. It was run from about 200 servers based in the Netherlands.
A security researcher spotted the botnet and alerted authorities. The hosting provider then took the servers offline because they were being used for illegal stuff. "The police then seized several botnet servers from a hosting provider for investigation," the NCSC said.
Reports link the botnet to ASOCKS, a Russian company. ASOCKS provides residential proxy services. These services let people hide their location online. They route internet traffic through other people's devices. This makes it harder to trace activity back to the original user.
Proxy services are often used for bad things. Think DDoS attacks, phishing, and scraping websites. It's about staying anonymous while doing shady stuff. Ars couldn't independently confirm the ASOCKS link, but it looks legit.
The NCSC had previously warned about these residential proxies. They said these proxies make it harder to stop cybercrime. It makes attacks look like normal traffic.
Security firm Human found connections between a botnet called Proxylib and ASOCKS in 2024. They found Proxylib-infected IP addresses and requests made to ASOCKS through infected devices.
Around 28 apps on Google Play had secretly enrolled almost 200,000 devices into this Russian proxy network. Users didn't even know it was happening.
ASOCKS hasn't responded to requests for comment. It's still unclear how all 17 million devices got roped into this botnet. Sometimes it's through software vulnerabilities. Other times, it's through malicious apps that trick users or hide the proxy behavior in fine print.



