we_are_coded.by CODE · The world, decoded
БГ
Who's who

The groups and the networks (Storm-2949, NetNut, residential proxies)

The BasicsUpdated on 13 July 2026we are coded

One department cons the employee. Another rents out the TV in your living room. Neither one touches code.

Checked on13 July 2026
In short: Storm-2949 is the code name Microsoft (the company behind Windows and the Azure cloud platform) gives to a group that broke into an entire organization's cloud infrastructure using only one employee's stolen identity - without a single line of malicious code. NetNut was a separate business: a network that sold access to over 2 million infected home devices, so criminals anywhere in the world could look like ordinary people to security systems. Both stories tell the same thing - crime now runs as a business split into specialties.

Storm-2949 doesn't break down doors, it knocks politely. It starts from a procedure every large company has - remote self-service password reset (SSPR). The attacker kicks off the reset in the employee's name, then calls or messages them, poses as support, and talks them into hitting "approve" on the two-factor authentication (MFA) prompt - exactly the safeguard meant to protect this step. From there it gets into Microsoft 365 (the company's mail and documents) and Azure (the cloud its own apps run on), digs through SharePoint and OneDrive - the organization's internal file archives - for VPN settings and passwords, and reaches Key Vault, the vault where companies keep the digital keys to everything else.

NetNut was the other half of the business - the infrastructure. The network didn't steal data, it sold cover: access to over two million devices in people's homes, mostly smart TVs and streaming boxes, quietly infected through tampered apps from a malware family known as Badbox. Route your traffic through a network like this, and it doesn't come out of a server in some foreign country - it comes out of the IP address of someone's TV in someone's living room. To security systems trained to flag "foreign" addresses, that looks perfectly normal - just a neighbor watching a show.

That's why the two names go together. A group like Storm-2949 doesn't build its own cover network - it rents access from someone like NetNut, the same way a criminal doesn't repaint his own car - he pays someone else with a garage. The division of labor is a clear sign: cybercrime is no longer a lone hobbyist's pastime in a dark room. It's a supply chain of vendors, each specialized in one link.

This year Google - the company behind the search engine and its cyber-intelligence team - and the FBI, the US federal police, together with the Shadowserver Foundation, which tracks malicious infrastructure worldwide, cut off NetNut and seized hundreds of domains. Storm-2949 remains active. Microsoft published its investigation recently and continues to track it.

The group that broke into an entire company's cloud didn't write a single line of malicious code - it just waited for one tired employee to hit "approve".

In plain terms

Organized crime has always had an office, bookkeeping, and paid leave for its staff - we just weren't looking that way. We were looking for a hoodie in front of a monitor in a dark room. Storm-2949 and NetNut show me exactly the opposite: one department does the social engineering, another sells the infrastructure, and somewhere in the middle sits a broker taking a cut. None of them touch code all day. They just do the job, go home, and come back tomorrow.

The most unpleasant part is the TV in my own living room. They didn't attack me - they rented me out without asking. While I'm watching a show, my device might quietly be carrying someone else's traffic to a bank in another country. That's not paranoia. That's a business model with millions of unwitting accomplices, most of whom will never find out they were ever part of it.

The visual is generated code art. No third-party images.
Official primary sources
→Google Threat Intelligence: the takedown of NetNut