HackMyIP
← Back to News
2026-07-06 The Hacker News

NetNut 2M-Device Proxy Botnet Disrupted; WhatsApp Usernames Spark Impersonation Fears

MalwarePrivacyThreat Intel

Google, the FBI, Lumen, and other partners moved this week to dismantle the NetNut residential proxy network—also tracked as Popa—disabling Google accounts and services used for malware command-and-control and updating Google Play Protect to flag apps incorporating the NetNut SDK. Investigators estimate the botnet spans at least 2 million compromised devices globally, including smart TVs and streaming boxes infected either pre-purchase or through Trojanized applications. Google identified NetNut plugin components embedded in large-scale operations like BADBOX 2.0, where attackers route malicious traffic through residential IPs to mask their origin. Users concerned about exposure on residential proxy networks can verify their connection integrity with a VPN/proxy detector and run a privacy checkup to surface any background leaks that such botnets could exploit.

WhatsApp officially opened global reservations for usernames, letting its three-billion-plus user base connect without sharing phone numbers—a meaningful privacy upgrade but one already attracting scrutiny. In India, WhatsApp's largest market, regulators and security researchers warned that the system could be abused to impersonate public authorities, banks, and government departments. Meta said it reserves handles for public figures, government entities, and known lookalikes, but has not clarified the full matching logic, leaving ambiguity about how easily a spoofed account could pass for a legitimate one. Identity hygiene matters here: users enabling the feature should pair a unique handle with a strong, unique password—verifiable through a password checker—and confirm account activity hasn't been tampered with.

Beyond those two lead stories, the week's recap captured a familiar pattern: ordinary surfaces—demo repos, reset flows, browser permission prompts—carrying outsized risk. AI agent platforms were manipulated into executing attacker-supplied instructions, while fake proof-of-concept exploits circulated as malware delivery vehicles, and browser-based ransomware campaigns kept refining social engineering playbooks. The connective tissue across every incident was misplaced trust—confidence extended one layer too early, whether to a streaming device on a home network, a username field, or a model that obeyed the wrong prompt. Defenders are advised to audit outbound DNS to catch covert proxy traffic with a DNS leak test, and to treat any unsolicited PoC download as hostile until proven otherwise.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →VPN & Proxy Detector →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →