NetNut proxy network disrupted, 2 million infected devices cut off

A Major Blow to Cybercrime: Google Disrupts NetNut Proxy Network, Cutting Off 2 Million Infected Devices

In a significant victory against cybercrime, a joint operation involving Google has taken down NetNut, a massive residential proxy network that provided access to millions of compromised Android devices. The botnet, also known as Popa, was used by threat actors and espionage groups to hide behind legitimate home internet addresses when launching attacks. With an estimated 2 million infected devices worldwide, including smart TVs and streaming boxes, the NetNut botnet has been a major concern for cybersecurity experts.

NetNut worked by compromising home systems and selling access to them, allowing malicious traffic to be routed through victims’ residential IP addresses. This made it difficult for internet service providers or online services to detect and block suspicious activity. Infected consumer devices served as exit nodes in the botnet, routing unauthorized network traffic through their residential IP addresses. As a result, many of these devices were flagged as suspicious or blocked by online services.

The NetNut botnet was dismantled after a coordinated effort involving Google, the FBI, Lumen Technologies, The Shadowserver Foundation, and other industry partners. Google played a crucial role in disrupting the botnet by disabling accounts and services on its infrastructure that NetNut operators used for malware command-and-control (C2). This move blocked access to critical backend infrastructure and protected users who were automatically warned and had infected applications disabled using Google Play Protect.

What’s particularly notable about this operation is the impact it may have on the wider proxy industry. NetNut has a robust reseller program that allows whitelabeling of its network, and many popular residential proxy services rely on NetNut for capacity. Disrupting one proxy service can prompt operators to purchase replacement capacity from competing providers, creating a cat-and-mouse game between law enforcement and cybercriminals.

The action against NetNut is part of Google’s ongoing commitment to dismantle residential proxy botnets. This effort follows the disruption of IPIDEA earlier this year. While it’s impossible to know for certain how many attacks have been prevented as a result, one thing is clear: the takedown of NetNut will have far-reaching consequences for cybercrime operations.

For individuals and organizations, the takeaway from this operation should be clear: even seemingly innocuous devices can become unwitting participants in malicious activities. It’s essential to stay vigilant and regularly test your security measures to ensure they’re effective. By doing so, you’ll be better equipped to prevent attacks before they occur – not just react after they’ve happened.


Source: Bleeping Computer — 2026-07-03