[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpNg4Pu7nxeL8n-Ke5a-5N0PlbBj9FMKlszFSxvRFW74":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"9f244598-e756-4e31-96ce-a7bedc938541","2-million-android-devices-hijacked-as-residential-proxy-botnet","9772ba19-976e-481b-9991-5e81df35a0d8","2 Million Android Devices Hijacked as Residential Proxy Botnet","Millions of Android devices — including smart TVs and streaming boxes — were silently compromised and enrolled into a residential proxy botnet called NetNut, enabling threat actors to route malicious traffic through legitimate home IP addresses. The infection likely spread through trojanized or malicious applications distributed outside of verified app stores, exploiting users' lack of awareness about third-party app risks. This matters because residential proxy botnets are particularly dangerous: their traffic blends in with normal user activity, making detection by security tools far more difficult. The disruption required a major coordinated effort between Google and the FBI, highlighting how costly remediation becomes when device hygiene and supply chain vetting are neglected from the start.","**Immediate actions:**\n- Audit and remove sideloaded or unverified applications from all Android and IoT devices in your environment.\n- Enable Google Play Protect and ensure automatic security scanning is active on all managed Android devices.\n- Block outbound traffic from IoT and smart TV devices to unknown or newly registered domains at the network perimeter.\n\n**Long-term improvements:**\n- Establish a Mobile Device Management (MDM) policy that restricts app installation to verified, corporate-approved sources only.\n- Maintain a complete inventory of all IoT and consumer-grade devices on your network, including smart TVs and streaming boxes.\n- Implement network segmentation to isolate IoT devices from critical business systems and sensitive data.\n\n**Detection measures:**\n- Deploy network traffic analysis tools to flag anomalous outbound connections or unusual data volumes from IoT devices.\n- Monitor DNS query logs for communication with newly registered or known botnet-associated domains.\n- Subscribe to threat intelligence feeds to receive timely indicators of compromise (IOCs) related to residential proxy botnets.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 1: Inventory and Control of Enterprise Assets","CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 CM-8: Information System Component Inventory","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SC-7: Boundary Protection","NIST SP 800-53 SA-12: Supply Chain Protection","NIST CSF DE.CM-1: Network Monitoring","GDPR Article 32: Security of Processing (for affected EU residents)","ITIL: Event Management and Incident Management practices","published","2026-07-03T18:20:23.68748+00:00","2026-07-03T18:20:23.37+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnetnut-proxy-network-disrupted-2-million-infected-devices-cut-off\u002F","netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-f5ed4b","NetNut proxy network disrupted, 2 million infected devices cut off",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[51,57],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"a9e701d2-0bfe-47a7-bb40-da332b8f6e3c","2026-07-05","afternoon","ThreatNoir Weekend Brief — July 5","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-05\u002Fthreatnoir-afternoon-brief-2026-07-05.mp3",{"id":58,"date":59,"edition":60,"title":61,"audio_url":62},"dc452d97-1c11-4442-942a-f9db033bed4f","2026-07-04","morning","ThreatNoir Weekend Brief — July 4","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-04\u002Fthreatnoir-morning-brief-2026-07-04.mp3"]