Joint Operation Disrupts NetNut Residential Proxy Botnet Built on 2 Million Infected Devices
A coordinated operation involving Google, the FBI, Lumen Technologies, The Shadowserver Foundation, and other industry partners has disrupted NetNut (also known as Popa), one of the world’s largest malicious residential proxy networks. According to the Google Threat Intelligence Group (GTIG), the botnet comprised at least two million compromised devices globally — including Android smart TVs and streaming boxes — infected through trojanized applications and botnets such as Badbox 2.0 that bundle proxy plugins, BleepingComputer reported.
Residential proxy networks let cybercriminals and espionage groups hide malicious traffic behind legitimate home internet addresses, routing attacks through victims’ devices so the traffic appears to come from ordinary households. GTIG said that in a single week last month it observed 316 distinct threat clusters using suspected NetNut exit nodes, employing the network to reach victim environments, conduct password-spraying attacks, and access their own infrastructure. The FBI seized domains used by the service, including netnut.com.
As part of the disruption, Google disabled accounts and services on its infrastructure that NetNut operators used for command-and-control, warned affected users, and disabled infected applications through Google Play Protect. The company also shared technical details of NetNut’s SDKs and backend infrastructure with platform providers, law enforcement, and researchers.
Google expects the takedown to ripple across the proxy industry, since NetNut ran an extensive reseller program that white-labeled its capacity to many popular residential proxy services. Researchers cautioned, however, that disrupting one provider often pushes operators to buy replacement capacity from competitors — a reminder of how interconnected the illicit proxy market has become. The action follows Google’s disruption of the IPIDEA proxy network earlier this year.