Executive Summary
In July 2026, Google, in collaboration with the U.S. Federal Bureau of Investigation (FBI), Lumen, and other partners, dismantled the NetNut residential proxy network, also known as Popa. This network, comprising over 2 million devices globally, exploited home devices like smart TVs and streaming boxes by distributing SDKs that transformed them into proxies for malicious traffic. The compromised devices were either pre-installed with malware before purchase or infected through user-downloaded applications containing hidden proxy code. This operation built upon a previous takedown of IPIDEA in January 2026.
The disruption of NetNut underscores the escalating threat posed by botnets leveraging residential devices to mask malicious activities. Such networks not only compromise individual privacy but also facilitate large-scale cyberattacks, making their neutralization a priority for global cybersecurity efforts.
Why This Matters Now
The NetNut incident highlights the urgent need for enhanced security measures in consumer IoT devices, as attackers increasingly exploit these platforms to build extensive proxy networks for malicious activities.
Attack Path Analysis
Attackers initiated the campaign by distributing malicious payloads through phishing emails and compromised websites, leading to the installation of botnet malware on victim systems. Once installed, the malware exploited vulnerabilities to escalate privileges, gaining higher-level access within the compromised environments. The attackers then moved laterally across networks, infecting additional systems and establishing a robust foothold. Command and control channels were set up using AI-powered services to evade detection, allowing attackers to manage the botnet remotely. Sensitive data was exfiltrated through encrypted channels to attacker-controlled servers. Finally, the attackers deployed ransomware to encrypt critical files, demanding payment for decryption keys.
Kill Chain Progression
Initial Compromise
Description
Attackers distributed malicious payloads via phishing emails and compromised websites, leading to the installation of botnet malware on victim systems.
MITRE ATT&CK® Techniques
Proxy
Mshta
Masquerading
Remote Access Software
Query Public AI Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Multi-vector campaigns targeting encrypted traffic and zero trust segmentation expose banking systems to lateral movement, data exfiltration, and regulatory compliance violations across hybrid cloud environments.
Health Care / Life Sciences
Proxy botnets and ransomware threats compromise patient data through east-west traffic vulnerabilities, threatening HIPAA compliance and critical healthcare infrastructure requiring enhanced egress security controls.
Telecommunications
Salt Typhoon references and encrypted traffic attacks directly impact telecom infrastructure, enabling command and control operations through compromised routing systems and vulnerable network segmentation boundaries.
Information Technology/IT
AI agent tricks and shadow AI exploitation target IT services through kubernetes security gaps, threatening cloud-native security fabrics and enabling sophisticated prompt injection attacks.
Sources
- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and Morehttps://thehackernews.com/2026/07/monday-recap-proxy-botnets-browser.htmlVerified
- One sock fits all: The use and abuse of the NSOCKS botnethttps://www.lumen.com/blog/en-us/use-abuse-nsocks-botnetVerified
- SystemBC malware turns infected VPS systems into proxy highwayhttps://www.bleepingcomputer.com/news/security/systembc-malware-turns-infected-vps-systems-into-proxy-highway/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise may still occur, CNSF would likely limit the malware's ability to communicate with other workloads, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Even if privilege escalation occurs, Zero Trust Segmentation would likely restrict the malware's access to other workloads, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely impede the attacker's ability to move laterally, thereby reducing the number of systems that could be compromised.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely detect and limit unauthorized command and control communications, reducing the attacker's ability to manage compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit unauthorized data exfiltration, reducing the amount of sensitive information that could be transmitted to external servers.
While initial encryption of files may occur, the overall impact would likely be limited due to constrained lateral movement and restricted access to critical systems.
Impact at a Glance
Affected Business Functions
- Network Infrastructure
- User Authentication
- Data Security
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of user credentials and sensitive data due to compromised devices acting as proxies.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads in real-time.
- • Enforce East-West Traffic Security to monitor and secure internal communications, mitigating the risk of lateral movement by attackers.



