Overview
In a landmark cybersecurity operation, Google, in collaboration with the FBI, Lumen Technologies, The Shadowserver Foundation, and other industry partners, has disrupted the NetNut residential proxy network, also known as Popa. This botnet hijacked over two million Android devices, including smart TVs and streaming boxes, turning them into proxy nodes for criminal and espionage activity.

How NetNut Operated
NetNut functioned as a residential proxy botnet, allowing threat actors to mask malicious traffic behind legitimate home IP addresses.
Key mechanics:
- Trojanized Applications — malware embedded in apps or pre‑installed on devices.
- Compromised Consumer Devices — infected smart TVs and streaming boxes became exit nodes.
- Residential IP Routing — attackers used victims’ home connections to hide their origin.
This setup enabled cybercriminals to conduct password‑spraying attacks, espionage operations, and infrastructure access while appearing as ordinary users.
The Disruption Operation
Google’s Threat Intelligence Group (GTIG) estimated that NetNut controlled at least two million infected devices globally.
The takedown involved:
- Domain Seizure by FBI — including netnut.com and related domains.
- Account and Service Shutdowns — Google blocked malware command‑and‑control (C2) channels.
- Play Protect Intervention — infected apps were disabled and users warned automatically.
- Intelligence Sharing — technical details shared with law enforcement and research partners.
GTIG reported that in one week alone, it observed 316 distinct threat clusters using NetNut exit nodes for cybercrime and espionage.
The Proxy Industry’s Interconnected Web
NetNut’s disruption revealed how deeply interconnected the residential proxy industry has become.
According to Mandiant’s Mark Karayan:
“The proxy industry is deeply interconnected where operators constantly buy and resell each other’s botnet capacity.”
When one network is taken down, operators often purchase replacement capacity from competitors, turning them into resellers and perpetuating the cycle.
Google’s Broader Mission
This action follows Google’s earlier disruption of the IPIDEA proxy network, signaling a sustained campaign against malicious residential proxy operators.
Google’s strategy focuses on:
- Cross‑Industry Collaboration to share threat intelligence.
- User Protection through Play Protect and malware screening.
- Infrastructure Hardening to prevent botnet resilience after takedowns.
Expert in the Cloud Insight
The NetNut takedown marks a turning point in the fight against proxy‑based cybercrime. By targeting SDKs and reseller infrastructure, Google and its partners are disrupting the economic engine behind botnet‑driven fraud.
For security leaders, the lesson is clear: consumer devices are now critical attack surfaces. Continuous device auditing, app vetting, and network visibility must be standard practice to counter the next generation of residential proxy abuse.
Leave a Reply