FBI Seizes NetNut Proxy Network Tied to Two-Million-Device Botnet

The FBI works with industry partners to seize hundreds of domains associated with NetNut, a major residential proxy service operated by the publicly-traded Israeli company Alarum Technologies. The takedown targets infrastructure tied to the Popa botnet, a network of at least two million compromised devices that includes smart TVs and streaming boxes hijacked without their owners' consent.

Security firms report that NetNut transforms everyday consumer devices into always-on proxy nodes, which are then rented out to users seeking to mask their digital footprints. Google's Threat Intelligence Group observes 316 distinct clusters of threat actors using suspected NetNut exit nodes in a single week, including cybercriminals and espionage groups conducting password sprays, advertising fraud, and account takeover attacks.

The seizure also highlights a broader danger to everyday consumers. When a home device becomes a proxy exit node, unauthorized traffic flows through it, potentially exposing other private devices on the same network to Internet threats. The FBI and IRS Criminal Investigation division thank Google, Lumen, Shadowserver, and other partners for their roles in dismantling the operation.

Read More at the original source →