Skip to main content
root@rebel:~$ cd /news/threats/google-disrupts-netnut-malicious-residential-proxy-network_
[TIMESTAMP: 2026-07-03 07:31 UTC] [AUTHOR: Runtime Rebel Intel] [SEVERITY: HIGH]

Google Disrupts NetNut Malicious Residential Proxy Network

AI-generated analysis
READ_TIME: 4 min read
Primary source: cloud.google.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

// executive briefing tl;dr
  • [01] Immediate impact: Millions of home devices are compromised, used as exit nodes for cybercrime and espionage activity.
  • [02] Affected systems: Smart TVs, streaming boxes, and Android devices unknowingly running NetNut SDKs for proxy operations.
  • [03] Remediation: Activate Google Play Protect and avoid applications offering payment for "unused bandwidth" or internet sharing.

Google’s Coordinated Disruption of NetNut Residential Proxy Network

Google, in a coordinated effort with the FBI, Lumen, and other partners, has undertaken significant action against the NetNut residential proxy network, also known as Popa. This disruption builds upon earlier successes, such as the action against the IPIDEA proxy network in January 2026, reinforcing Google’s sustained commitment to dismantling malicious residential proxy networks. The actions taken are expected to cause substantial degradation to NetNut’s operations, disrupting malicious residential proxy networks and reducing the available pool of compromised devices by millions.

Technical Details and Impact of NetNut Operations

NetNut stands as one of the largest and most widely used residential proxy networks globally. Google Threat Intelligence Group (GTIG) estimates the network size to be at least 2 million devices. These networks function by selling access to IP addresses owned by Internet Service Providers (ISPs), allowing malicious actors to mask their true origin by routing traffic through unsuspecting users’ home IP addresses. This provides anonymity for a range of illicit activities, from cybercriminal operations to state-sponsored espionage.

Residential proxy networks like NetNut achieve their scale by enrolling home devices as “exit nodes.” This occurs either through pre-installed malware on consumer electronics, such as smart TVs and streaming boxes, or when users unknowingly download applications containing hidden proxy code. Public reporting, corroborated by Google, indicates that NetNut populates its botnet via SDKs embedded in such devices. GTIG has also been successful in identifying NetNut botnet plugin components within larger botnets like Badbox 2.0.

The implications for device owners are severe. Their home IP addresses become launchpads for hacking, password spray attacks, and unauthorized activities, potentially flagging their legitimate traffic as suspicious or leading to service blocks. Furthermore, when a device becomes an exit node, unauthorized network traffic traverses it, creating a risk of Lateral Movement within the same home network, exposing other private devices to internet threats. GTIG observed 316 distinct threat clusters utilizing suspected NetNut exit nodes in a single week during June 2026, including cybercriminal and espionage groups. NetNut has also been documented in public reports as a vector for infecting devices with variants of [Mirai DDoS botnets](https://en.wikipedia.org/wiki/Mirai_(malware)). The network’s robust reseller program, which enables the white-labeling of its botnet, complicates the disruption efforts, as operators may simply acquire capacity from competitors.

Google’s Disruption Strategy and Actions Taken

Google’s actions against NetNut involved several strategic initiatives:

  • Infrastructure Disablement: Google disabled accounts and associated Google services used by NetNut for malware C2, directly violating Google’s Terms of Service and Acceptable Use Policy.
  • Intelligence Sharing: Technical intelligence regarding NetNut SDKs and backend C2 infrastructure was shared with platform providers, law enforcement, and research firms. This aims to foster ecosystem-wide awareness and enable broader enforcement actions.
  • User Protection: Google Play Protect, Android’s built-in security protection, was updated to automatically warn users and disable applications known to incorporate NetNut SDKs. This protection extends to preventing future installation attempts, safeguarding Android users on certified devices.

These coordinated actions have significantly degraded NetNut’s capacity. Google’s ongoing observation of the NetNut network’s composition and how its peers adapt to this disruption is crucial for sustained success against this fluid and interconnected industry.

Actionable Recommendations for Mitigating Risks of Residential Proxy Networks

For Consumers

Consumers play a vital role in preventing the proliferation of malicious residential proxy networks. Mitigating risks of residential proxy networks starts with informed choices and active security practices:

  • Exercise Caution with Apps: Be extremely wary of applications that offer payment in exchange for “unused bandwidth” or “sharing your internet.” These are primary vectors for malicious proxy networks to grow and can expose your home network to vulnerabilities.
  • Prioritize Official Sources: Stick to official app stores for all software downloads. Review permissions for third-party VPNs and proxy applications carefully.
  • Activate Security Features: Ensure built-in security protections, such as Google Play Protect on Android devices, are active and up-to-date.
  • Reputable Devices: When purchasing connected devices like set-top boxes, confirm they are from reputable manufacturers and are built with official, certified operating systems (e.g., official Android TV OS with Play Protect certification). Check the Android TV website for a list of partners and follow these steps to verify Play Protect certification on your Android device.

For Organizations and the Ecosystem

For mobile platforms, ISPs, and other tech platforms, continued collaboration and intelligence sharing are essential. Disrupting these networks requires a collective effort to block malicious C2 infrastructure and adapt to the evolving tactics of proxy operators. Point-in-time disruptions are effective, but a sustained, coordinated strategy targeting the interconnected infrastructure of various providers is necessary to achieve lasting impact in this complex and rapidly expanding industry.

Advertisement

Advertisement