Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
BotNet

NetNut Botnet Disrupted: FBI and Google Cut Off 2 Million Compromised Devices

By ogwatermelon
July 6, 2026 4 Min Read
0
July 5, 2026

A coordinated operation involving Google, the FBI, and industry partners has disrupted NetNut, one of the largest residential proxy networks in the world. The botnet, also known as Popa, compromised at least 2 million Android devices including smart TVs and streaming boxes. Consequently, cybercriminals and espionage groups have lost access to millions of residential IP addresses they used to hide malicious traffic.

What Happened: NetNut Residential Proxy Botnet Disrupted in Global Operation

On July 3, 2026, Google announced a joint operation that significantly degraded the NetNut residential proxy network. The Google Threat Intelligence Group (GTIG) worked alongside the FBI, Lumen Technologies, The Shadowserver Foundation, and other partners to dismantle infrastructure supporting at least 2 million compromised devices globally.

The FBI seized key domains used by NetNut, including netnut.com. Furthermore, Google disabled accounts and services on its infrastructure that the operators used for malware command-and-control. This action blocked access to critical backend infrastructure and cut off the botnet’s ability to manage infected devices.

Residential proxy networks like NetNut are a growing threat in the cybersecurity landscape. They compromise consumer devices and sell access to them, allowing threat actors to route malicious traffic through legitimate home internet addresses. Therefore, attacks appear to originate from ordinary residential connections, making detection and attribution far more difficult.

Technical Details of the NetNut Botnet

NetNut populated its network by distributing software development kits embedded in consumer devices. These devices commonly included smart TVs, streaming boxes, and other Android-powered hardware. The malware was either pre-installed before purchase or added via trojanized applications downloaded by users.

Infected devices served as exit nodes in the proxy network. They routed unauthorized network traffic through residential IP addresses. This caused some devices to be flagged by internet service providers or blocked by online services. Moreover, users often remained unaware that their home devices were being exploited.

Google identified NetNut botnet plugin components for large-scale botnets such as Badbox 2.0. These components packaged proxy plugins alongside other malicious functionality. The network also maintained a robust reseller program that allowed whitelabeling of its proxy capacity. Many popular residential proxy brands were likely reselling NetNut infrastructure under different names.

According to GTIG, in one week last month researchers observed 316 distinct threat clusters using suspected NetNut exit nodes. These clusters included both cybercriminal operations and state-sponsored espionage groups.

Business and Operational Impact

The NetNut disruption has significant implications for both consumers and enterprises. The impact extends across multiple sectors and threat actor communities.

  • Consumer privacy: Millions of home devices were silently exploited, routing unknown traffic through residential connections
  • Enterprise security: Threat actors used NetNut exit nodes to access victim infrastructure, conduct password-spraying attacks, and hide attack origins
  • ISP reputation: Residential IP addresses were flagged or blocked, potentially affecting legitimate users on compromised networks
  • Proxy industry: The disruption will likely trigger proxy operators to purchase capacity from competitors, reshaping the residential proxy ecosystem

Google expects this disruption to create a ripple effect across the residential proxy industry. However, observations from the earlier IPIDEA disruption showed that operators often respond by buying replacement capacity from competing providers. Therefore, sustained pressure across multiple interconnected networks is necessary for lasting impact.

Mitigation and Recommendations

Immediate Actions for Consumers

  1. Check Android devices for suspicious applications and remove any unknown apps
  2. Update streaming boxes, smart TVs, and other connected devices to the latest firmware
  3. Review Google Play Protect warnings and act on any alerts about disabled applications
  4. Change home router passwords and ensure firmware is current
  5. Monitor internet usage for unusual spikes in bandwidth or latency

Immediate Actions for Defenders

  1. Review logs for traffic originating from known residential proxy IP ranges
  2. Implement device fingerprinting to detect anomalies in user agent strings and behaviors
  3. Monitor for password-spraying campaigns that may have used NetNut exit nodes
  4. Share threat intelligence on NetNut SDKs and backend infrastructure with industry partners
  5. Evaluate proxy detection services to identify traffic from compromised residential devices

Bottom line: The NetNut disruption is a major win for defenders, but the residential proxy ecosystem is deeply interconnected. Organizations should treat residential proxy traffic as a potential risk factor and implement detection controls accordingly. Consumers must remain vigilant about the applications they install on connected home devices.

Incident Summary

Incident: NetNut / Popa Residential Proxy Botnet Disruption
Affected Systems: Android smart TVs, streaming boxes, and other consumer devices (2M+ estimated)
Disclosure Date: July 3, 2026
Action Taken: Domain seizure, C2 disruption, Google Play Protect enforcement
Coordinated By: Google, FBI, Lumen Technologies, The Shadowserver Foundation

References

  1. Ionut Ilascu, “NetNut proxy network disrupted, 2 million infected devices cut off,” BleepingComputer, July 3, 2026, https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/, accessed July 5, 2026.
  2. Google Threat Intelligence Group, “Google’s Continued Disruption of Malicious Residential Proxy Networks,” Google Cloud Blog, July 3, 2026, https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks, accessed July 5, 2026.
  3. Brian Krebs, “Popa Botnet Linked to Publicly Traded Israeli Firm,” KrebsOnSecurity, June 2026, https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/, accessed July 5, 2026.

Tags:

Botnet
Author

ogwatermelon

Follow Me
Other Articles
Previous

Seven FatFs Vulnerabilities Expose Millions of Embedded Devices to Memory Corruption and Code Execution

Next

TrojPix Attack Exfiltrates Data From Air-Gapped Systems via Video Cables

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.