The images in this article were generated with artificial intelligence. How we publish
The recent operation by the Dutch authorities that dismantled a botnet responsible for enslaving millions of devices again shows an uncomfortable reality:. According to the police and the Netherlands National Cyber Security Centre (NCSC), the malicious network would have affected at least 17 million devices and supported more than 200 servers located in the country as a backend infrastructure.
The intervention included the seizure of some of these servers by the police, and the accommodation provider who provided the infrastructure took off-line service after finding their criminal use. Although the authorities did not explicitly disseminate the commercial name of the service involved, local media have pointed out to Asocks, a residential and mobile proxies as one of the actors linked to the operation. Investigations of intelligence equipment such as that of HUMAN / Satori had identified campaigns involving infected Android devices and proxyware applications.

It is important to distinguish between legitimate uses and illicit activities: residential proxies have valid applications such as removing geographical restrictions or performing quality of service tests, but the same technical model is used by malicious actors who rent access to committed devices to mask attacks, advertising fraud or platform abuse. This ambiguity makes the proxies market an opaque ecosystem where responsibility and traceability are scarce.
The technical and operational impact of a botnet of this magnitude is not limited to direct damage: it generates malicious traffic that degrades the reliability of services, causes black lists of residential IPs, hinders forensic investigation and forces suppliers and companies to invest in detection and filtering. In addition, it strengthens the relationship between privacy and security: legitimate users seeking anonymity may be affected by widespread blocking measures.
For domestic users, the lesson is clear: digital hygiene remains the first line of defence. Keep the router operating system and firmware up to date, change default passwords, deactivate unnecessary remote management services and use WPA2 / WPA3 on Wi-Fi significantly reduces the risk that a device will become part of a botnet. On mobile phones, it is appropriate to install applications only from official stores and to review permissions and abnormal data consumption or battery as a sign of proxyware.
Companies and network administrators should raise the bet: visibility and segmentation. Filtering out traffic (egress filtering), blocking unnecessary ports and protocols, segmenting IoT in separate VLANs and deploying EDR / IDS solutions that detect persistent proxy patterns and connections to residential networks are practical measures. It is also recommended to require contractual clauses for accommodation and proxy service providers to ensure transparency and remedies against abuse.
Platform providers and application marketers have a key responsibility: to monitor and veto proxy applications that are distributed with dubious monetization techniques or without clear user consent. Device manufacturers should also incorporate default security controls, such as the imposition of single passwords and automatic firmware updates.

At the regulatory level, the incident exposes the need for greater traceability in the proxy market and minimum obligations for intermediaries. An effective approach combines technical measures, international collaboration in police action and legal requirements for suppliers providing abuse-sensitive infrastructure.
For those who want to deepen how botnets work and what general recommendations exist at the institutional level, it is useful to consult sources such as the United States Infrastructure and Cybersecurity Security Centre ( CISA on botnets) and specialized coverage of the news and its technical context in cybersecurity media ( BleepingComputer).
If you suspect that your devices are part of an unauthorized network, disconnect them from the network, restore passwords and reinstall the software from clean sources; for companies, contact your managed security provider or a forensic service. Prevention, early detection and collaboration between users, companies, suppliers and authorities are the only way to reduce the black market for committed device-based proxies and to mitigate the damage these illicit infrastructure causes to the confidence and operation of the Internet.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...