Stories
Slash Boxes
Comments

SoylentNews is people

posted by mrpg on Tuesday July 07, @01:13PM   Printer-friendly
from the operation-nutcracker dept.

NetNut cracked as Google and FBI target 2 million-device botnet

Tech companies working with US law enforcement "significantly degraded" the NetNut residential proxy network as part of an ongoing effort to disrupt the tools cybercriminals use to conceal their activity, say researchers.

The work was carried out by Google, Lumen, Shadowserver, the FBI, and others, and marks a continuation of the IPIDEA proxy network disruption from January.

According to Google Cloud, those working on the operation believe NetNut was among the most popular residential proxy network providers and had at least 2 million devices enrolled in its botnet, comprising mainly small TV-streaming hardware. Crims often use residential proxy networks to make it look like their traffic is actually coming from legit homes and businesses.

In the same way that other residential proxy networks expand their pool of enrolled devices, NetNut distributed its own SDK via these devices.

Proxy providers often approach users under the guise of monetizing their spare bandwidth, paying them a fee in exchange for letting their SDK run on their devices.


Original Submission

This discussion was created by mrpg (5708) for logged-in users only. Log in and try again!
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 1, Interesting) by Anonymous Coward on Tuesday July 07, @02:41PM (5 children)

    by Anonymous Coward on Tuesday July 07, @02:41PM (#1447538)

    Maybe I'm short of acronyms. But why would a user want to run a software development kit on his device? Hey bro, you get the latest text editor and Perl syntax highlighting, we give you $1 if you install that.

    • (Score: 2) by looorg on Tuesday July 07, @02:47PM (4 children)

      by looorg (578) on Tuesday July 07, @02:47PM (#1447540)

      Proxy providers often approach users under the guise of monetizing their spare bandwidth, paying them a fee in exchange for letting their SDK run on their devices.

      I think that is exactly what it sounds like and what they are doing. Perhaps the sum is larger then $1 tho.

      • (Score: 4, Insightful) by looorg on Tuesday July 07, @02:50PM (1 child)

        by looorg (578) on Tuesday July 07, @02:50PM (#1447541)

        Or they just sneak it in there with some "cheap" IPTV device or they offer them "free wi-fi" or something such. They don't need to know all that is running on the box. Most people do not know all things their devices or computers are doing. Those are probably more likely then they are walking up to people and offering them $1 to run some software on their devices.

        • (Score: 3, Insightful) by anubi on Tuesday July 07, @07:10PM

          by anubi (2828) on Tuesday July 07, @07:10PM (#1447574) Journal

          I don't see we have much of a choice.

          Damn near anything I have, except some hobby stuff whose innards are in the public domain, come with proprietary software and EULA specifying that someone else has control of the software in my machine, they may change it at any time, and any attempts I do to even as much as disassemble it to verify it is a clear violation of the Digital Millinium Copyright Act.

          This is a paradigm based on fear of being reported by compliance verification agentic software running in any business-grade machine.

          We still have hobby grade machines we can still trust, but I still have an extreme distrust of that which I am prohibited from verifying it with trusted tools.

          In the early days of computing, we had debuggers to help clean up buggy code. Now the bugs are deliberately inserted and debuggers buggered as part of federal regulation to protect copyright at the expense of being able to verify that the protected code isn't a Trojan horse.

          We completely failed to pass legislation that assigns accountability for software integrity along with customer accountability for honoring terms and conditions.

          Why the public still tolerates such an imbalance of rights enforcement is still beyond me.

          This DMCA thing was well known for being a bad idea for everyone else before it was passed.

          Passed by those we voted to represent us

          This is our problem. It's called "indifference".

          We didn't recognize a rat when we saw it. Now our house is overrun with rats. And we tolerate enshittified things.

          --
          "Prove all things; hold fast that which is good." [KJV: I Thessalonians 5:21]
      • (Score: 1, Funny) by Anonymous Coward on Tuesday July 07, @04:12PM (1 child)

        by Anonymous Coward on Tuesday July 07, @04:12PM (#1447557)

        Hmmm, how many people would be interested to run a text editor on their TV box?

  • (Score: 4, Informative) by fliptop on Tuesday July 07, @03:50PM (2 children)

    by fliptop (1666) on Tuesday July 07, @03:50PM (#1447553) Journal

    They should point that effort at their own 34.0.0.0/10 block, which is out of control w/ port scans, spam and httpd vulnerability probes. What the actual F?

    --
    Ever had a belch so satisfying you have to blow your nose afterward?
    • (Score: 0) by Anonymous Coward on Tuesday July 07, @04:16PM

      by Anonymous Coward on Tuesday July 07, @04:16PM (#1447558)

      They should point that effort at their own 34.0.0.0/10 block... What the actual F?

      They're chasing down the competition instead.

    • (Score: 3, Informative) by zocalo on Tuesday July 07, @08:39PM

      by zocalo (302) on Tuesday July 07, @08:39PM (#1447584)
      Yeah, I've noticed that range spike too, and maybe a few others at Google starting to ramp up as well. Kinda interesting it's only a small subset of the total Google Cloud IP space, which would tend to imply something specific to the DCs hosting that range that have allowed the bad actors to gain a foothold rather than a generic hack against Google's infrastructure, but whatever, it's been going on for months and Google is still to get on top it, so time to give some thought to whether Google really is "too big to block".

      In this case, it's a user content range (almost all the malicious hosts tend to have hostnames of the form "[in-addr IP].bc.googleusercontent.com") - a generic sub-domain you should probably be rejecting all email from anyway, which solves the spam aspect of the problem. For the rest, the chances are very few of those IPs are going to be initiating any legitimate comms with your hosts unless you are specifically hosting services of VMs assigned to IPs within that range. Just drop inbound comms from that range at the perimeter, let your firewall manage state for any sessions you establish to it, and the fallout will most probably be somewhere between zero and none.
      --
      UNIX? They're not even circumcised! Savages!
  • (Score: 1, Funny) by Anonymous Coward on Tuesday July 07, @04:33PM (1 child)

    by Anonymous Coward on Tuesday July 07, @04:33PM (#1447562)

    How does this help the Trump or Kash Patel? Sounds like a bunch of woke BS.

(1)