Google hobbled a proxy infrastructure network it claimed was being used to distribute malware and other activities.
Working with Lumen and the FBI, the cloud giant took action against NetNut (also known as Popa), a residential proxy network that sells the ability to route traffic through IP addresses owned by internet service providers (ISPs). The trio alleges that attackers were using the service to mask malicious behavior by hijacking addresses from across the world to act as a “launchpad for hacking and other unauthorized activities.”
The hyperscaler confirmed it had disabled Google accounts and associated Google services used by NetNut for malware command and control, while also sharing technical intelligence with both partners and law enforcement to boost ecosystem-wide efforts against
Google said the coordinated actions have caused “significant degradation” to the proxy network, reducing the potential available pool of devices by “millions.”
Proxy networks are essentially an alternative to virtual private networks (VPNs). Where the latter forms an encrypted connection between a device and the internet, with traffic routed through secure servers, a proxy acts as a gateway between endpoints, rerouting traffic at the application level.
Potential enterprise uses for a proxy network (sometimes referred to as an intermediary network) include geo-testing and data collection or scanning incoming and outgoing traffic, with security tools like Cisco’s Umbrella or Zscaler employed to check for potentially malicious files.
NetNut counted among the largest residential proxy networks, with Google’s Threat Intelligence Group estimating it was made up of at least two million devices.
The hyperscaler cited Krebs on Security reporting that NetNut had been employed in devices around homes like smart TVs and streaming boxes, employing them to power large-scale botnets.
In a single week in June alone, Google’s Intelligence Group observed more than 300 distinct threat clusters using suspected NetNut exit nodes. Cybercriminal and espionage groups were recorded using NetNut to mask their origin IP address when accessing victim environments.
The action marks the latest in Google’s ongoing actions against proxy networks.
In January, it went after IPIDEA, performing similar account suspensions against what it claimed at the time was the world’s largest malicious proxy network.
Following that prior takedown, the hyperscaler said it observed that individual networks “can appear resilient.”
“When faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller,” a Google blog suggests. “We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers. We will continue to observe the composition of the NetNut network and map out how its peers adapt to this action.”
Comments