The FBI has seized NetNut — a proxy network based on the Popa botnet comprising two million compromised devices — after security firms documented its connection to malware on smart TVs and streaming devices in June.
Operation Endgame has cleaned 14,971 compromised WordPress websites from the SocGholish malware network, which is attributed to the Russian cybercrime group Evil Corp.
The four-year-old Popa botnet, used to monetize compromised TV boxes, is traced technically and personally to the Israeli proxy provider NetNut (Alarum Technologies).
JDY is not a classical DDoS botnet, but rather an industrialized reconnaissance infrastructure that abuses edge devices as distributed scanners to identify targets before exploitation.