NetNut proxy network disrupted, 2 million infected devices cut off
2026-07-04T01:23:29Z•e7a219410f3955869af82b354022d8b023f79dcbafb95ab92a85db9261ac0c9a
ARTokenAndroid compromiseCISAChocoPoCCisco Unified CMClickFixConsentFixEvilTokensFortiBleedINC ransomwareLynxMFA bypassMicrosoft 365NetNutOperaPaste ProtectRATSharePoint RCEShinyHunters breach','Medtronic'active exploitationbotnetcredential theftphishing-as-a-serviceresidential proxytrojanized PoC
What happened
Multiple high-impact incidents and active campaigns were reported: law enforcement and Google disrupted the NetNut residential proxy network that abused ~2 million compromised Android devices; ARToken (a phishing‑as‑a‑service affiliate of EvilTokens) exposed an extensive Microsoft 365 phishing toolkit; ConsentFix and ClickFix techniques enable near‑instant Microsoft 365 token theft and MFA bypass, prompting mitigations such as Opera's Paste Protect; CISA warned of active exploitation of a high‑severity Microsoft SharePoint RCE patched in May, and Cisco confirmed active exploitation of a recent
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- e7a219410f3955869af82b354022d8b023f79dcbafb95ab92a85db9261ac0c9a
- Enrichment time
- 2026-07-04T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.