Desk live·
ForensicPost
Ransomware/Enforcement/File 26-0528

Dutch Police Seize 200 Servers Behind Proxy Network of 17 Million Devices

Dutch authorities seized 200 servers behind a residential proxy service reported to have infected at least 17 million devices across 163 countries. Proxy networks are what make stolen credentials usable.

Constructed geometry · not a chart of case data
JurisdictionNetherlandsthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAsocks proxy network
ActorUnattributed
S. Rosler11 min readConfidence: high2 sources reviewed

On 28 and 29 May 2026, Dutch law enforcement dismantled one of the largest criminal proxy networks recorded, seizing 200 command servers from a Netherlands hosting provider. The service, reported as Russia-linked and operating as Asocks, is described as having infected at least 17 million devices across 163 countries.

The Proxy Is What Makes A Stolen Credential Work

Every identity-led intrusion this desk has filed depends on the attacker’s traffic looking ordinary. A credential presented from a data centre in another country is an obvious anomaly; the same credential presented from a residential connection in the victim’s own city is not.

Residential proxy networks sell exactly that: the ability to appear to be a normal domestic user. It is the component that defeats impossible-travel checks, geographic risk scoring and reputation blocking, all in one purchase.

The Supply Is Somebody’s Home Connection

The 17 million devices are the inventory. Some are compromised outright, as in the botnet file at 26-0302. Others are enrolled through bundled software where a consumer accepted terms permitting their connection to be resold.

The second category is the more troubling one, because it is not obviously illegal. A person who installed a free application may be routing criminal traffic through their home line, with their address in the logs of whatever it reached.

Why This Is A Good Target

This desk argued in the laundering file at 26-0614 that the concentrated commercial layers are the ones worth disrupting. Proxy infrastructure is another: intrusion capability is widely distributed, but 17 million exit nodes with a billing system behind them is a business, and businesses have servers and administrators.

How we reported this

Compiled from published reporting, listed below. Device and country figures are as reported by the investigating authorities. Corrections: corrections@forensicpost.com.

Sources
  1. Botnet takedown dismantled 200 servers: Asocks malware still runs on 17 million devicesTech Times
  2. Residential-proxy botnets and DDoS, 2026 updateNokia
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary