NetNut proxy network disrupted, 2 million infected devices cut off

2026-07-04T07:23:28Zc367198eeb0a9baad9c5196747a471cff96dc711d192ecb2a83fef474726760f
ARTokenAndroidChocoPoCCisco Unified CMClickFixConsentFixEvilTokensFortiBleedINCLynxMFA-bypassMicrosoft 365NetNutPaste-ProtectPhaaSRATSharePoint RCEShinyHuntersbotnetcredential-theftdata-breachphishingransomwareremote-code-executionresidential-proxy

What happened

Multiple high-impact incidents and active threats were reported: law enforcement and Google disrupted the NetNut residential-proxy network controlling ~2 million compromised Android devices; CISA and others warned that a Microsoft SharePoint RCE patched in May and a Cisco Unified CM flaw patched in June are being actively exploited; the FortiBleed credential-theft campaign has been tied to INC/Lynx ransomware operators; and a ShinyHunters data exposure affected Medtronic. New attacker tooling and tactics are also emerging: the ARToken PhaaS (affiliate of EvilTokens) exposes a Microsoft 365 ph‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c367198eeb0a9baad9c5196747a471cff96dc711d192ecb2a83fef474726760f
Enrichment time
2026-07-04T07:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · NetNut proxy network disrupted, 2 million infected devices cut off · Baitaphish