
Massive Residential Proxy Network Netnut Infects Millions of Smart Devices, Enabling Cybercrime
A large-scale residential proxy network called Netnut (also known as Papa) has infected between 1 and 2 million smart TVs, streaming boxes, and cheap routers, hijacking users' internet connections without explicit consent. The network, linked to publicly traded company Alarium Technologies, enables threat actors to route malicious traffic—including Mirai botnet variants, Badbox 2.0, and password spray attacks—through compromised devices, masking their origin. Google’s threat intelligence group reported 316 separate threat groups using Netnut in a single week, while researchers found no evidence of user consent in over 20 apps distributing the malware. Google disrupted the operation by shutting down Netnut’s command-and-control servers and enabling Play Protect to block infected apps, significantly degrading the network. Separately, Cloudflare introduced a monetization gateway in July 2026, allowing websites to charge AI crawlers via cryptocurrency using HTTP 402 status codes, though this risks blocking legitimate search engine indexing. A new macOS infostealer, Pam Stealer, disguises itself as the clipboard manager Maccy, while Rustock malware targets routers, IP cameras, and Android devices for DDoS attacks. The U.S. government is offering a $10 million reward for information on a Russian state-linked cyber group that compromised Signal and WhatsApp accounts of journalists and officials. A 19-year-old Scattered Spider member, Peter Stokes, was extradited to the U.S. in April 2025 for hacking high-profile companies, including MGM and Caesars.