Google and the FBI Take Down NetNut, a Residential Proxy Botnet Built From 2 Million Home Devices

Google, the FBI, and industry partners have disrupted NetNut, a residential proxy network built on at least 2 million hijacked home devices. In one June week, 316 threat clusters rode its exit nodes. Why the takedown matters, and why defenders should expect churn rather than extinction.

Share
Google and the FBI Take Down NetNut, a Residential Proxy Botnet Built From 2 Million Home Devices

Google went back into the residential proxy ecosystem this week and pulled another giant off the board. Working with the FBI, Lumen's Black Lotus Labs, The Shadowserver Foundation, and other partners, Google's Threat Intelligence Group disrupted NetNut, a residential proxy network it also tracks as Popa. The scale is the headline: GTIG puts the network at a minimum of 2 million devices spread across the world, most of them ordinary household hardware like smart TVs and streaming boxes.

If this feels familiar, it should. It is the second strike in six months. Google dismantled IPIDEA in January 2026, calling it one of the largest residential proxy networks in the world, and made it clear at the time that more was coming. NetNut is the follow-through.

What actually happened

Google says it did three things. It disabled the Google accounts and services NetNut was using for malware command and control, a straightforward terms of service enforcement. It pushed Google Play Protect to automatically warn users and disable applications known to carry NetNut SDKs, with future install attempts blocked as well. And it shared the technical intelligence on those SDKs and the backend C2 infrastructure with platform providers, law enforcement, and research firms so the rest of the ecosystem can enforce too.

The result, in Google's assessment, is significant degradation of both the proxy network and the business behind it, with the operator's available device pool reduced by millions.

Why a proxy network is a defender problem

Residential proxies sell one thing: the ability to route traffic through IP addresses that belong to real internet service providers and real homes. To your SIEM, a login riding a NetNut exit node does not look like attacker infrastructure. It looks like a customer on a couch.

That breaks a lot of quiet assumptions. IP reputation scoring, geo-based conditional access, block-known-VPN-ranges rules - all of it degrades when the attacker's traffic originates from a smart TV in a residential subnet in the right country. It is exactly why these networks are so popular for password spraying and for slipping into victim environments without tripping alarms.

The demand side is not hypothetical. In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, spanning both cybercriminal and espionage operations. For the January IPIDEA takedown the equivalent figure was even starker: over 550 individual threat groups in a seven day window, including actors from China, DPRK, Iran, and Russia.

ZDW infographic on the NetNut takedown: a residential proxy botnet of at least 2 million home devices disrupted by Google and the FBI.

How your TV ends up in a botnet

The supply side is uglier. NetNut grows by distributing SDKs that get embedded into apps and devices, commonly the cheap smart TVs and streaming boxes people plug in and forget. Public reporting by KrebsOnSecurity, confirmed by Google, laid out that pipeline, and GTIG has also identified NetNut plugin components inside large-scale botnets like Badbox 2.0. Some devices ship pre-compromised. Others get enrolled when someone installs an app promising to pay them for "unused bandwidth."

Once a device becomes an exit node, two bad things happen at once. Traffic the owner never sees transits their home IP address, which can get their legitimate use flagged or blocked by providers. And traffic can flow toward the device as well, meaning other private devices on the same home network are effectively exposed to the internet. Reports from Synthient, Spur, Nokia Deepfield and others have documented NetNut being used to infect devices with Mirai DDoS variants. Your streaming box is the beachhead; your whole network is the prize.

The part Google admits out loud

Here is the refreshingly honest bit of the announcement. NetNut does not just sell under its own name. It runs a robust reseller program that lets other companies whitelabel the network, and Google says it has high confidence that many popular residential proxy brands are, in fact, whitelabeled NetNut.

Google also learned something else watching the aftermath of the IPIDEA action: when a proxy operator's own botnet gets degraded, they just start buying capacity from a competitor and act as a reseller themselves. That is why individual networks look so resilient - the ecosystem quietly backfills. Google's stated conclusion is that lasting disruption means hitting several interconnected providers at once, and it intends to keep mapping how NetNut's peers adapt to this action.

For defenders, the translation is simple: the takedown is real, but treat it as churn, not extinction. The exit nodes you were seeing last month will move.

Action Items

  • Do not rely on IP reputation as your first line of defense. Residential proxy traffic is built to defeat it. Weight behavioral signals, device fingerprinting, impossible travel, and token anomalies instead.
  • Look for password spraying and authentication attempts originating from residential ASNs, particularly many-accounts, low-velocity patterns that rotate through home IPs.
  • Refresh your proxy and anonymizer detection feeds now. With the takedown done, expect heavy exit-node churn as operators buy capacity from the competition - stale lists degrade quickly.
  • GTIG has made indicators of compromise available to registered users in a GTI Collection. If residential proxy abuse is in your threat model, pulling those into your blocklists is worth your time.
  • At home, and for your users: be extremely cautious of any app offering payment for "unused bandwidth" or "sharing your internet," stick to official app stores, and buy streaming hardware from reputable manufacturers with Play Protect certification.

The through-line from January to now is that Google has decided residential proxies are infrastructure worth attacking, not just observing. Two networks down, an ecosystem of resellers to go - and 2 million households who never knew they were part of the fight.

Read more