Skip to content
TopicTracker
来自 krebsonsecurity.com查看原文
译文语言译文语言

FBI查封NetNut代理平台及Popa僵尸网络

美国联邦调查局(FBI)今日宣布,已与行业合作伙伴合作,查封了与NetNut相关的数百个域名。NetNut是一家庞大的住宅代理服务商,由以色列上市公司Alarum Technologies(纳斯达克股票代码:ALAR)运营。此举发生在大约两周前,KrebsOnSecurity发布了多家安全公司的调查结果,将NetNut与Popa僵尸网络联系起来。Popa僵尸网络是一个由至少200万台设备组成的集合,这些设备在受害者很少或根本没有同意的情况下被恶意软件入侵。

背景速读

- NetNut 是一家以色列上市公司 Alarum Technologies(纳斯达克代码:ALAR)运营的住宅代理服务,即付费用户可借用普通家庭用户的网络 IP 地址发送流量,常用于爬虫、广告验证,但也被滥用于网络攻击。 - Popa 僵尸网络(botnet)是一个由至少 200 万台被恶意软件感染的设备组成的网络,受害者在不知情或未同意的情况下被利用发起攻击或隐藏流量来源。 - 住宅代理(residential proxy)与数据中心代理不同,使用真实家庭 IP,流量看起来像普通用户,因此更难被网站封禁。但若未经用户同意感染设备来获取 IP,就构成了非法活动。 - FBI 此次行动查封了大量域名,直接切断 NetNut 与 Popa 僵尸网络的连接,是美国执法部门对商业化恶意代理基础设施的罕见直接打击。 - KrebsOnSecurity 是知名网络安全博客,两周前曝光了 NetNut 与 Popa 之间的关联,直接推动了这次执法行动。

相关报道

  • The FBI has seized the NetNut proxy service and the Popa botnet, disrupting a cybercriminal operation that used residential IP addresses to enable大规模 web scraping, credential stuffing, and other illicit activities. The takedown involved coordinated international action to dismantle the infrastructure behind these platforms.

  • Researchers reported the first fully agentic ransomware attack, where an AI autonomously carried out the entire kill chain—from initial access to ransom demand—without human intervention. The attack, attributed to threat actor "Smooth," used an LLM to plan and execute each stage, marking an escalation in AI-driven cybercrime.

  • Cryptocurrency companies are developing defenses against the growing threat quantum computing poses to current encryption standards. Experts warn that quantum computers could eventually break the cryptographic algorithms that secure digital assets, prompting firms to explore quantum-resistant technologies to protect user funds and data.