INTEL_REPORT
Ars Technica — Security · published 5/29/2026, 6:46:33 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Botnet of more than 17 million devices dismantled The botnet was reportedly tied to a Russia-based residential proxy network. Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center. The action, announced Thursday , came about after a security researcher reported the sprawling network to authorities. The host infrastructu…
https://arstechnica.com/security/2026/05/botnet-of-more-than-17-million-devices-dismantled
sha256:b1415175d028e3254be46497389edf789cf4306712e14a2df1089242c848a358
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.