Google took coordinated action against the NetNut residential proxy network by disabling accounts and sharing intelligence on its SDKs and C2 infrastructure. Because many other brands resell this whitelabeled botnet, a single disruption is insufficient; operators simply purchase capacity from competitors when their own networks are degraded.
Google’s Continued Disruption of Malicious Residential Proxy Networks
Detection engineers can use shared indicators for NetNut's SDKs and C2 to identify malicious proxy activity and compromised home devices used as exit nodes.
Read the original at Google Cloud — Threat Intelligence →
Subscribe
Short, high-signal articles and news summarized — at a frequency of your choosing. One click to subscribe.