Dutch Police Take Down C2 Infrastructure Behind 17-Million-Device Botnet

Authorities in the Netherlands seized command-and-control servers powering a botnet spanning infected computers, phones, and tablets — infrastructure allegedly rented out as a residential proxy network for criminal operations.

ThreatVectr Newsdesk· 2 min read
Dutch Police Take Down C2 Infrastructure Behind 17-Million-Device Botnet
Share

Dutch law enforcement dismantled the backend of a botnet that, at its peak, corralled roughly 17 million compromised devices. The seized assets were command-and-control servers. Without them, the network loses its nervous system.

The botnet's alleged commercial model was residential proxying — a well-established cybercrime service in which victims' devices are quietly recruited to route third-party traffic. Buyers get IP addresses that look like ordinary home internet connections. That makes fraud, credential stuffing, and ad-click manipulation much harder to block by IP reputation alone. The criminal economy for residential proxy access is substantial; legitimate proxy services charge by the gigabyte, and underground equivalents command comparable rates at scale.

Authorities have not publicly named suspects or filed charges that are visible in court records at time of publication. The Dutch National Police — Politie — confirmed the seizure. Seventeen million devices across computers, smartphones, and tablets represents a significant footprint. For context, the Netherlands has roughly 18 million people.

How devices got recruited into this botnet is not fully detailed in the disclosure. Typical vectors include malware bundled with cracked software, phishing payloads, and exploitation of unpatched consumer routers. Once enrolled, infected devices often show no obvious symptoms — their owners have no idea they are fronting someone else's traffic.

The residential proxy abuse model matters because it sits upstream of many other crimes. Fraudsters use it to bypass geographic restrictions and rate limits. Ransomware operators use it to probe targets without burning known-malicious IP ranges. Initial access brokers use it to validate stolen credentials quietly. Seizing the C2 layer does not reach those downstream buyers, but it forces them to source proxy capacity elsewhere.

Takedowns of this kind tend to be disruptive rather than terminal. Operators rebuild, rebrand, or sell infrastructure to successors. The devices themselves remain vulnerable until owners reimage or patch them — something most consumers never do unprompted.

© 2026 Threat Vectr