Google Dismantles NetNut Residential Proxy

Overview

In a landmark cybersecurity operation, Google, in collaboration with the FBI, Lumen Technologies, and other industry partners, has dismantled the NetNut residential proxy network, also known as Popa. The network is believed to have compromised over 2 million home devices worldwide, turning them into unwitting nodes for criminal proxy traffic.

Operation Details

Google’s action targeted NetNut’s malware command‑and‑control (C2) infrastructure, disabling Google accounts and services used to coordinate the botnet — a direct violation of its Terms of Service.

Key steps included:

  • Account and service shutdowns to cut off malware control channels.
  • Technical intelligence sharing with law enforcement and research partners.
  • Google Play Protect update to warn users and disable apps bundled with NetNut SDKs.

This operation builds on Google’s January 2026 disruption of the IPIDEA proxy network, signaling a sustained campaign against malicious residential proxy operators.

The NetNut–Popa Connection

Independent investigations by KrebsOnSecurity and Qurium linked the Popa botnet directly to NetNut, a subsidiary of Alarum Technologies Ltd (NASDAQ: ALAR).

Popa functions as a plugin within the larger Vo1d botnet, targeting unofficial Android TV boxes bundled with pirated streaming apps like CRICFy, DooFlix, and Flixoid.

  • Synthient analysis confirmed outbound traffic from Popa devices to NetNut clients.
  • Black Lotus Labs estimates show 1.5 to 2.5 million distinct IPs cycling daily across 250–300 controller domains.

Despite NetNut’s claims of “consensual bandwidth‑sharing,” proxy‑tracking services like Spur and Synthient found little evidence of meaningful user consent or corporate verification.

Global Impact

Google’s Threat Intelligence Group observed 316 distinct threat clusters in June 2026 using NetNut exit nodes for:

  • Password spraying and credential stuffing.
  • Infrastructure obfuscation for espionage and cybercrime.
  • Mirai‑variant DDoS attacks on home networks.

Home devices became proxy nodes through pre‑installed malware or hidden SDKs in free apps, exposing entire households to external threats.

Google’s Recommendations

To protect against residential proxy abuse, Google advises:

  • Avoid apps offering payment for unused bandwidth.
  • Use official app stores and verify Play Protect certification.
  • Check connected devices like smart TVs and streaming boxes for malware.
  • Support cross‑industry intelligence sharing to disrupt reseller networks.

Google emphasized that the residential proxy industry is deeply interconnected, with operators reselling capacity from rivals to maintain resilience after takedowns — a pattern already seen post‑IPIDEA.

Expert in the Cloud Insight

The NetNut takedown marks a turning point in the fight against proxy‑based cybercrime. By targeting SDKs and reseller infrastructure, Google and its partners are disrupting the economic engine behind botnet‑driven fraud.

For security leaders, the lesson is clear: consumer devices are now critical attack surfaces. Continuous device auditing, app vetting, and network visibility must be standard practice to counter the next generation of residential proxy abuse.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.