NetNut cracked as Google and FBI target 2 million-device botnet
Tech companies working with US law enforcement "significantly degraded" the NetNut residential proxy network as part of an ongoing effort to disrupt the tools cybercriminals use to conceal their activity, say researchers.
The work was carried out by Google, Lumen, Shadowserver, the FBI, and others, and marks a continuation of the IPIDEA proxy network disruption from January.
According to Google Cloud, those working on the operation believe NetNut was among the most popular residential proxy network providers and had at least 2 million devices enrolled in its botnet, comprising mainly small TV-streaming hardware. Crims often use residential proxy networks to make it look like their traffic is actually coming from legit homes and businesses.
In the same way that other residential proxy networks expand their pool of enrolled devices, NetNut distributed its own SDK via these devices.
Proxy providers often approach users under the guise of monetizing their spare bandwidth, paying them a fee in exchange for letting their SDK run on their devices.
(Score: 1, Interesting) by Anonymous Coward on Tuesday July 07, @02:41PM (5 children)
Maybe I'm short of acronyms. But why would a user want to run a software development kit on his device? Hey bro, you get the latest text editor and Perl syntax highlighting, we give you $1 if you install that.
(Score: 2) by looorg on Tuesday July 07, @02:47PM (4 children)
I think that is exactly what it sounds like and what they are doing. Perhaps the sum is larger then $1 tho.
(Score: 4, Insightful) by looorg on Tuesday July 07, @02:50PM (1 child)
Or they just sneak it in there with some "cheap" IPTV device or they offer them "free wi-fi" or something such. They don't need to know all that is running on the box. Most people do not know all things their devices or computers are doing. Those are probably more likely then they are walking up to people and offering them $1 to run some software on their devices.
(Score: 3, Insightful) by anubi on Tuesday July 07, @07:10PM
I don't see we have much of a choice.
Damn near anything I have, except some hobby stuff whose innards are in the public domain, come with proprietary software and EULA specifying that someone else has control of the software in my machine, they may change it at any time, and any attempts I do to even as much as disassemble it to verify it is a clear violation of the Digital Millinium Copyright Act.
This is a paradigm based on fear of being reported by compliance verification agentic software running in any business-grade machine.
We still have hobby grade machines we can still trust, but I still have an extreme distrust of that which I am prohibited from verifying it with trusted tools.
In the early days of computing, we had debuggers to help clean up buggy code. Now the bugs are deliberately inserted and debuggers buggered as part of federal regulation to protect copyright at the expense of being able to verify that the protected code isn't a Trojan horse.
We completely failed to pass legislation that assigns accountability for software integrity along with customer accountability for honoring terms and conditions.
Why the public still tolerates such an imbalance of rights enforcement is still beyond me.
This DMCA thing was well known for being a bad idea for everyone else before it was passed.
Passed by those we voted to represent us
This is our problem. It's called "indifference".
We didn't recognize a rat when we saw it. Now our house is overrun with rats. And we tolerate enshittified things.
"Prove all things; hold fast that which is good." [KJV: I Thessalonians 5:21]
(Score: 1, Funny) by Anonymous Coward on Tuesday July 07, @04:12PM (1 child)
Hmmm, how many people would be interested to run a text editor on their TV box?
(Score: 2) by turgid on Tuesday July 07, @08:46PM
Oh, I dunno. Vim would be cool for editing the crontab that does the nightly download of all the shows I want to watch later.
I refuse to engage in a battle of wits with an unarmed opponent [wikipedia.org].
(Score: 4, Informative) by fliptop on Tuesday July 07, @03:50PM (2 children)
They should point that effort at their own 34.0.0.0/10 block, which is out of control w/ port scans, spam and httpd vulnerability probes. What the actual F?
Ever had a belch so satisfying you have to blow your nose afterward?
(Score: 0) by Anonymous Coward on Tuesday July 07, @04:16PM
They're chasing down the competition instead.
(Score: 3, Informative) by zocalo on Tuesday July 07, @08:39PM
In this case, it's a user content range (almost all the malicious hosts tend to have hostnames of the form "[in-addr IP].bc.googleusercontent.com") - a generic sub-domain you should probably be rejecting all email from anyway, which solves the spam aspect of the problem. For the rest, the chances are very few of those IPs are going to be initiating any legitimate comms with your hosts unless you are specifically hosting services of VMs assigned to IPs within that range. Just drop inbound comms from that range at the perimeter, let your firewall manage state for any sessions you establish to it, and the fallout will most probably be somewhere between zero and none.
UNIX? They're not even circumcised! Savages!
(Score: 1, Funny) by Anonymous Coward on Tuesday July 07, @04:33PM (1 child)
How does this help the Trump or Kash Patel? Sounds like a bunch of woke BS.
(Score: 2) by turgid on Tuesday July 07, @08:49PM
See you in Valhalla [youtube.com], patriot!
I refuse to engage in a battle of wits with an unarmed opponent [wikipedia.org].