NetNut proxy network disrupted, 2 million infected devices cut off

2026-07-04T01:23:29Ze7a219410f3955869af82b354022d8b023f79dcbafb95ab92a85db9261ac0c9a
ARTokenAndroid compromiseCISAChocoPoCCisco Unified CMClickFixConsentFixEvilTokensFortiBleedINC ransomwareLynxMFA bypassMicrosoft 365NetNutOperaPaste ProtectRATSharePoint RCEShinyHunters breach','Medtronic'active exploitationbotnetcredential theftphishing-as-a-serviceresidential proxytrojanized PoC

What happened

Multiple high-impact incidents and active campaigns were reported: law enforcement and Google disrupted the NetNut residential proxy network that abused ~2 million compromised Android devices; ARToken (a phishing‑as‑a‑service affiliate of EvilTokens) exposed an extensive Microsoft 365 phishing toolkit; ConsentFix and ClickFix techniques enable near‑instant Microsoft 365 token theft and MFA bypass, prompting mitigations such as Opera's Paste Protect; CISA warned of active exploitation of a high‑severity Microsoft SharePoint RCE patched in May, and Cisco confirmed active exploitation of a recent

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
e7a219410f3955869af82b354022d8b023f79dcbafb95ab92a85db9261ac0c9a
Enrichment time
2026-07-04T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · NetNut proxy network disrupted, 2 million infected devices cut off · Baitaphish