On 28 and 29 May 2026, Dutch law enforcement dismantled one of the largest criminal proxy networks recorded, seizing 200 command servers from a Netherlands hosting provider. The service, reported as Russia-linked and operating as Asocks, is described as having infected at least 17 million devices across 163 countries.
The Proxy Is What Makes A Stolen Credential Work
Every identity-led intrusion this desk has filed depends on the attacker’s traffic looking ordinary. A credential presented from a data centre in another country is an obvious anomaly; the same credential presented from a residential connection in the victim’s own city is not.
Residential proxy networks sell exactly that: the ability to appear to be a normal domestic user. It is the component that defeats impossible-travel checks, geographic risk scoring and reputation blocking, all in one purchase.
The Supply Is Somebody’s Home Connection
The 17 million devices are the inventory. Some are compromised outright, as in the botnet file at 26-0302. Others are enrolled through bundled software where a consumer accepted terms permitting their connection to be resold.
The second category is the more troubling one, because it is not obviously illegal. A person who installed a free application may be routing criminal traffic through their home line, with their address in the logs of whatever it reached.
Why This Is A Good Target
This desk argued in the laundering file at 26-0614 that the concentrated commercial layers are the ones worth disrupting. Proxy infrastructure is another: intrusion capability is widely distributed, but 17 million exit nodes with a billing system behind them is a business, and businesses have servers and administrators.
Compiled from published reporting, listed below. Device and country figures are as reported by the investigating authorities. Corrections: corrections@forensicpost.com.