NetNut proxy network disrupted, 2 million infected devices cut off

2026-07-04T13:23:28Zd82f6759b1ffc66a9f46892d3095523b1550dd2d76995bf427764e2fe9f38466
ARTokenChocoPoCCisco-Unified-CMClickFixConsentFixEvilTokensFortiBleedLynxMFA-bypassMicrosoft-365NetNutOAuthPaste-ProtectPhaaSRATScattered-SpiderSharePoint-RCEShinyHuntersactive-exploitationbotnetdata-breachphishingransomwareresidential-proxytrojanized-PoC

What happened

A batch of high-impact security stories: law enforcement (with Google) disrupted the NetNut residential proxy network, cutting off access to ~2 million compromised Android devices and streaming boxes. A new phishing-as-a-service called ARToken—tied to the EvilTokens ecosystem—exposes a comprehensive Microsoft 365 phishing toolkit; related OAuth-based MFA bypasses (ConsentFix and ClickFix) are highlighted and being mitigated (e.g., Opera's new Paste Protect). CISA and vendors warn that a high-severity Microsoft SharePoint RCE patched in May is now actively exploited, and Cisco confirmed active/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d82f6759b1ffc66a9f46892d3095523b1550dd2d76995bf427764e2fe9f38466
Enrichment time
2026-07-04T13:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.