A massive residential proxy network, known as NetNut or Popa, has been disrupted by a joint operation involving Google and other industry partners. This move has cut off access to at least 2 million compromised devices worldwide, including smart TVs and streaming boxes, which were being used for malicious activities by cybercriminals and espionage groups.
NetNut worked by compromising home systems and selling access to them, allowing threat actors to conceal their malicious traffic by routing it through the victims’ residential IP addresses. This made it difficult to detect and track the origin of attacks. Typically, home devices became part of the botnet after being infected with malware that was either pre-installed before purchase or added via malicious or trojanized applications downloaded by the user.
The compromised devices served as exit nodes in the botnet, routing unauthorized network traffic through their residential IP addresses. This caused the devices to be flagged as suspicious or blocked by internet service providers or online services. The NetNut proxy service was used by hundreds of threat actors and considered one of the largest networks in the world.
A coordinated effort involving Google, the FBI, Lumen Technologies, The Shadowserver Foundation, and other industry partners was needed to dismantle the NetNut botnet. Google disabled the accounts and services on its infrastructure that NetNut operators used for malware command-and-control (C2), blocking access to critical backend infrastructure. The company also protected users by automatically warning them and disabling infected applications using Google Play Protect.
Google shared technical details on NetNut’s software development kits (SDKs) and backend C2 infrastructure with platform providers, law enforcement agencies, and cybersecurity researchers. This move is expected to have a broader impact in the proxy industry as NetNut had a robust reseller program that allowed whitelabeling of its network. Many popular residential proxy services are fueled by NetNut.
The disruption of NetNut follows Google’s commitment to dismantle residential proxy botnets. Disrupting one proxy service often prompts operators to purchase replacement capacity from competing providers, turning them into resellers. This highlights the complexity and interconnectedness of the proxy industry.
The incident is a reminder that even seemingly legitimate devices can be compromised and used for malicious activities. It underscores the importance of security awareness and vigilance in protecting against such threats. As part of your cybersecurity posture, it’s essential to regularly test your defenses against potential vulnerabilities, including conducting breach and attack simulation tests to ensure your SIEM and EDR rules are effective.
In this context, Google’s efforts to disrupt NetNut and dismantle residential proxy botnets demonstrate the importance of collaboration between industry partners, law enforcement agencies, and cybersecurity researchers in mitigating such threats.
Source: Bleeping Computer — 2026-07-03