Geopolitics Technology · · 8 min read

Dutch Police Dismantle 17 Million-Device Botnet Masquerading as Commercial Proxy Service

Operation marks largest residential proxy takedown on record, exposing how consumer IoT devices become infrastructure for state-adjacent cybercrime.

Dutch authorities seized control of a botnet comprising at least 17 million compromised IoT devices this week, dismantling what security researchers describe as one of the largest residential proxy networks ever documented. The operation targeted infrastructure underpinning Asocks, a commercial proxy service that converted millions of routers, smartphones, and connected devices into anonymising nodes for threat actors conducting phishing campaigns, credential stuffing, and distributed denial-of-service attacks.

The scale of the compromise underscores a structural vulnerability in consumer networks: residential IP addresses, traditionally trusted by fraud detection systems, now serve as infrastructure for cyberespionage and financially motivated crime. Unlike datacenter proxies that security teams routinely flag, residential IPs blend into legitimate traffic patterns, enabling attackers to bypass geofencing, rate limits, and impossible-travel alerts.

Asocks Botnet by the Numbers
Infected Devices17M+
Control Servers (Netherlands)200
Advertised IP Pool7M addresses
Monthly Subscription$5–$15

How Consumer Devices Became Proxy Infrastructure

The botnet operated through PROXYLIB, a Go-based library embedded in Android applications via the LumiApps SDK, according to Help Net Security. Device owners downloaded seemingly legitimate apps—often utilities or games—that silently converted their phones and home routers into proxy nodes. Traffic routed through these compromised endpoints appeared to originate from residential ISPs rather than suspicious hosting providers.

Asocks marketed itself as a universal proxy service offering corporate, residential, and mobile proxies across 150 locations, claiming a client base of 100,000 subscribers, per BleepingComputer. The service charged $5 to $15 monthly for access to IP pools that customers used to scrape competitor pricing, test geo-restricted content, or—more commonly—conduct credential stuffing attacks against financial platforms.

“Additionally, the devices of unsuspecting users can become part of such proxy networks, often without their knowledge. In this way, consumers are unknowingly part of cybercrime.”

— NCSC-NL, Dutch National Cyber Security Centre

The Dutch National Cyber Security Centre noted the misuse of residential proxies “makes it more difficult to map digital threats and attacks,” warning that organisational resilience faces pressure as attack scale increases, reported The Register. The 200 servers controlling the botnet were physically located in the Netherlands, enabling Dutch police to execute simultaneous seizures that severed command-and-control communications.

Legal Exposure for Unwitting Device Owners

Device owners whose hardware participated in the proxy network face potential legal liability despite having no knowledge of the compromise. Riley Kilmer, co-founder of internet intelligence firm Spur, cautioned that “if they use your network for illegal activity, there’s a chance that Law Enforcement could come knocking at your door.”

This liability risk extends beyond theoretical concern. The botnet facilitated attacks including distributed denial-of-service campaigns, phishing infrastructure hosting, brute-force authentication attempts, and malware distribution, according to Cybernews. Each compromised device effectively became an unwitting participant in criminal operations, with traffic originating from residential addresses that victims could trace back to specific households.

Context

The Asocks takedown follows a wave of residential proxy disruptions in early 2026. In March, authorities dismantled SocksEscort, which offered access to 369,000 IP addresses across 163 countries via AVRecon malware affecting roughly 280,000 routers. In January, Google Threat Intelligence documented over 550 distinct threat groups exploiting the IPIDEA residential proxy network in a single week before its disruption. The Kimwolf botnet, active since October 2025, infected 2 million devices and penetrated 25% of Infoblox customer networks, demonstrating how residential proxies enable corporate espionage at scale.

The Geopolitical Dimension

While Dutch authorities have not formally attributed the botnet to state actors, the infrastructure design and operational scale suggest coordination beyond typical cybercriminal capabilities. Google Cloud Blog analysis of the IPIDEA network, disrupted in January, revealed that state-sponsored groups routinely exploit residential proxies to mask reconnaissance activity and evade attribution.

The Netherlands location of control servers adds complexity to attribution efforts. Server hosting in jurisdictions with robust legal frameworks allows operators to maintain plausible deniability while benefiting from infrastructure stability and connectivity. The botnet’s capacity—17 million devices generating traffic indistinguishable from legitimate residential users—represents a capability more valuable for intelligence collection than financial fraud.

July 2025
BADBOX 2.0 Discovery
Researchers identified 10+ million compromised Android TV boxes forming botnet infrastructure. Inland Cyber Defense Clinic filed lawsuit documenting supply chain compromise.
October 2025
Kimwolf Emerges
Botnet infected 2M+ devices, penetrating 25% of enterprise networks tracked by Infoblox. Demonstrated corporate espionage applications of residential proxies.
January 2026
IPIDEA Takedown
Google documented 550+ threat groups exploiting residential proxy network before disruption. First major operation targeting proxy-as-a-service infrastructure.
March 2026
SocksEscort Disrupted
Authorities seized infrastructure offering 369,000 IPs across 163 countries. AVRecon malware compromised 280,000 routers to power proxy network.
29 May 2026
Asocks Seizure
Dutch police dismantled 17M-device botnet, marking largest residential proxy operation disrupted to date. 200 control servers seized.

Remediation Challenges at Consumer Scale

The distributed nature of the compromise creates remediation challenges that extend far beyond server seizures. Infected devices span global ISP networks, multiple device manufacturers, and varied operating systems. Unlike enterprise breaches where IT teams can push patches to managed endpoints, consumer IoT devices often lack update mechanisms or remain on obsolete firmware indefinitely.

Security researchers identified the PROXYLIB infection vector through analysis of Android applications, but iOS devices, routers with outdated firmware, and smart home devices likely remain compromised. Device owners receive no automated notification that their hardware participated in the botnet, and many infected endpoints will continue attempting to reconnect to command-and-control infrastructure that no longer exists.

Key Implications
  • Residential IP addresses no longer function as reliable trust signals for fraud detection systems
  • Consumer devices represent critical infrastructure vulnerability exploitable for state-adjacent operations
  • Legal frameworks lack clarity on liability when compromised personal devices facilitate crime
  • IoT security failures compound as device proliferation outpaces patching capabilities
  • Proxy-as-a-service business model enables cybercrime scaling previously requiring nation-state resources

What to Watch

The NCSC-NL published analysis immediately before the takedown announcement describing residential proxy abuse as a “worrying trend,” suggesting additional disruption operations remain in progress. European law enforcement coordination through Europol indicates a broader campaign targeting proxy-as-a-service infrastructure rather than isolated enforcement actions.

Device manufacturers face pressure to implement secure-by-default configurations and mandatory update mechanisms, particularly for routers and IoT endpoints that rarely receive security patches post-sale. The Federal Communications Commission has proposed supply chain security requirements for network equipment, but consumer devices remain largely unregulated despite demonstrated exploitation at scale.

For enterprises, the Asocks disruption reinforces the inadequacy of IP-based trust models. Security architectures that assume residential IP addresses indicate legitimate users now require additional verification layers—device fingerprinting, behavioural analysis, and continuous authentication—to distinguish human operators from botnet-proxied connections. The 17 million compromised devices represent less than 1% of global internet-connected endpoints, suggesting residential proxy infrastructure continues operating at scale beyond disrupted networks.