An international task force dismantled a botnet comprising more than 400,000 compromised home and small-office routers, seizing its command-and-control infrastructure across several hosting providers.

The botnet powered DDoS-for-hire services and a residential proxy network rented to other criminal groups seeking to disguise their traffic as ordinary consumer connections.

The malware exploited default credentials and years-old firmware vulnerabilities. Authorities obtained court authorization to issue self-removal commands to infected devices, a technique used in several recent botnet takedowns.

ISPs in affected countries are notifying customers with vulnerable devices. Researchers stress that unmanaged consumer network hardware remains one of the internet's largest attack surfaces.