botnet6 articles
NadMesh Botnet Is Raiding Exposed AI Services for Cloud Keys, and the Numbers Don't Add Up
A Go-based botnet called NadMesh, discovered in early July 2025, systematically scans for exposed AI services (such as ComfyUI, Ollama, and n8n) to steal cloud credentials, Kubernetes tokens, and environment variable secrets, with the operator's own dashboard claiming over 3,800 harvested AWS keys. While the botnet prioritises AI service endpoints and MCP tools, the majority of its observed exploit traffic actually targets more traditional attack surfaces like Docker APIs and Jenkins consoles, with MCP exploitation accounting for less than 1% of recorded attempts. Defenders are urged to place exposed services behind authentication, check systems for persistence artefacts, and immediately revoke — not merely rotate — any credentials that may have been exposed.
Google and FBI Knock Out NetNut Proxy Network Backed by Millions of Infected Devices
Google, the FBI, and other partners disrupted NetNut (also known as Popa), a residential proxy network comprising over 2 million infected Android devices, including smart TVs and streaming boxes compromised through malicious apps. The network, linked to Israeli firm Alarum Technologies, rented proxy access to cybercriminals and espionage groups, with 316 distinct threat clusters observed using it in a single week. Google's actions included disabling associated accounts, dismantling backend infrastructure, and removing infected apps via Google Play Protect, resulting in a significant reduction in the botnet's available devices.
Botnets in Your Living Room, Ransomware in Your Browser, and AI That Follows the Wrong Orders: This Week in Security
This week's cybersecurity recap highlights how attackers exploited ordinary, trusted systems rather than sophisticated vulnerabilities. Key incidents included Google and the FBI disrupting the NetNut residential proxy botnet (comprising at least 2 million devices), a fake GitHub PoC repository delivering the ChocoPoC RAT via a malicious dependency, and AI-generated browser ransomware leveraging Chromium's File System Access API. Additional notable stories covered WhatsApp username impersonation concerns, a Scattered Spider suspect extradited to the US, and multiple phishing-as-a-service toolkits emerging in the wild. The overarching theme was misplaced trust — in home devices, clean-looking code, identity reset flows, and browser permissions — underscoring that attackers need little more than a familiar, overlooked entry point.
Google and FBI Kneecap NetNut's 2 Million-Device Proxy Botnet
Google, the FBI, and other partners have significantly disrupted NetNut, a residential proxy network that had enrolled at least 2 million devices — mostly TV-streaming hardware — into a botnet used by cybercriminals to disguise malicious traffic as coming from ordinary homes and businesses. In a single week in June 2026, over 316 distinct threat clusters, including cybercriminal and espionage groups, were observed using NetNut exit nodes for activities such as password spraying and masking their origins. Researchers warn that lasting disruption is difficult, as proxy operators tend to simply buy capacity from competitors when their own networks are degraded, and call for broader, coordinated efforts involving ISPs and technology platforms.
C0XMO Botnet Exploits DD-WRT Routers, Evicts Rival Malware to Claim Territory
C0XMO is a new, advanced variant of the Gafgyt botnet that exploits CVE-2021-27137, a buffer overflow vulnerability in DD-WRT router firmware, to spread across multiple device types and CPU architectures. It supports 19 DDoS attack methods, uses a Python-based scanner to brute-force credentials and move laterally across networks, and actively eliminates rival malware and security tools to maintain dominance on infected devices. Researchers at Fortinet describe it as significantly more sophisticated than typical IoT botnets, recommending that users keep devices patched, use strong credentials, and disable unnecessary remote access.
Dutch Authorities Axe 17-Million-Device Botnet Tied to Russian Proxy Firm
Dutch authorities, in a joint operation between police and the National Cyber Security Center, dismantled a botnet comprising over 17 million devices managed by 200 servers, after a security researcher reported the network. The botnet has been linked to ASOCKS, a Russia-based residential proxy service reportedly used for criminal activities such as DDoS attacks, phishing, and hiding users' identities. The host infrastructure, based in the Netherlands, was seized and taken offline by the hosting provider.