Dettaglio notizia
| Data | 07/07/2026 |
| Titolo | Google and FBI Disrupt NetNut Residential Proxy Network Used by Malware Operators |
| Contesto | Google said it disrupted NetNut—also known as Popa—a large residential proxy network that investigators linked to malware delivery, command-and-control activity, and efforts by cybercriminal and espionage actors to mask their origin IP addresses while accessing victim environments. Working with the FBI, Lumen, and other partners, Google disabled accounts and services allegedly used by the operation, shared technical intelligence on NetNut SDKs and backend infrastructure, and used Google Play Protect against apps that incorporated the NetNut SDK. Google estimated the network relied on at least 2 million devices and said 316 threat clusters used suspected NetNut exit nodes during a single week in June. The coordinated action also included FBI seizures of NetNut-associated domains, a move that parent company Alarum Technologies said disrupted part of the service and could materially affect operations and financial results if the outage persists. Google said the operation significantly degraded the network and cut its available device pool by millions, describing the move as part of a broader campaign against malicious proxy providers after an earlier action against IPIDEA. The disruption is being viewed as a blow not only to a botnet-linked service but also to the broader supply of residential proxy infrastructure relied on by multiple threat actors. |
| Fonte | https://mallory.ai/stories/019f36e8-0635-7787-8724-2441a8f208df |
| Discussione? | Parliamone sul Forum |