One department cons the employee. Another rents out the TV in your living room. Neither one touches code.
Storm-2949 doesn't break down doors, it knocks politely. It starts from a procedure every large company has - remote self-service password reset (SSPR). The attacker kicks off the reset in the employee's name, then calls or messages them, poses as support, and talks them into hitting "approve" on the two-factor authentication (MFA) prompt - exactly the safeguard meant to protect this step. From there it gets into Microsoft 365 (the company's mail and documents) and Azure (the cloud its own apps run on), digs through SharePoint and OneDrive - the organization's internal file archives - for VPN settings and passwords, and reaches Key Vault, the vault where companies keep the digital keys to everything else.
NetNut was the other half of the business - the infrastructure. The network didn't steal data, it sold cover: access to over two million devices in people's homes, mostly smart TVs and streaming boxes, quietly infected through tampered apps from a malware family known as Badbox. Route your traffic through a network like this, and it doesn't come out of a server in some foreign country - it comes out of the IP address of someone's TV in someone's living room. To security systems trained to flag "foreign" addresses, that looks perfectly normal - just a neighbor watching a show.
That's why the two names go together. A group like Storm-2949 doesn't build its own cover network - it rents access from someone like NetNut, the same way a criminal doesn't repaint his own car - he pays someone else with a garage. The division of labor is a clear sign: cybercrime is no longer a lone hobbyist's pastime in a dark room. It's a supply chain of vendors, each specialized in one link.
This year Google - the company behind the search engine and its cyber-intelligence team - and the FBI, the US federal police, together with the Shadowserver Foundation, which tracks malicious infrastructure worldwide, cut off NetNut and seized hundreds of domains. Storm-2949 remains active. Microsoft published its investigation recently and continues to track it.
In plain terms
Organized crime has always had an office, bookkeeping, and paid leave for its staff - we just weren't looking that way. We were looking for a hoodie in front of a monitor in a dark room. Storm-2949 and NetNut show me exactly the opposite: one department does the social engineering, another sells the infrastructure, and somewhere in the middle sits a broker taking a cut. None of them touch code all day. They just do the job, go home, and come back tomorrow.
The most unpleasant part is the TV in my own living room. They didn't attack me - they rented me out without asking. While I'm watching a show, my device might quietly be carrying someone else's traffic to a bank in another country. That's not paranoia. That's a business model with millions of unwitting accomplices, most of whom will never find out they were ever part of it.