IC Operations & Tradecraft — 2026-07-06

Google and FBI Disrupt NetNut Residential Proxy Network of Two Million Infected Devices Used by Cybercriminal and Espionage Groups

BLUFDisrupting Google-hosted C2 degrades NetNut's current infrastructure, but intact reseller and whitelabeling channels make reconstitution by early October likely given durable criminal and espionage demand for residential proxy access.

Google, in coordination with the FBI, Lumen Technologies, and the Shadowserver Foundation, disrupted the NetNut residential proxy network on July 3, disabling Google accounts and services NetNut used for malware command-and-control and triggering an FBI takedown of the netnut.com domain 12. Google Threat Intelligence Group estimates NetNut, also known as Popa, controls at least two million infected devices worldwide, including smart TVs and streaming boxes compromised through trojanized applications and Badbox 2.0 botnet plugins 23. GTIG recorded 316 distinct threat clusters using suspected NetNut exit nodes over a single week in June, including both cybercriminal and espionage groups conducting password-spray attacks and masking access to victim environments 23. Google also pushed Play Protect updates to automatically warn users and disable Android applications carrying NetNut SDKs, and it shared technical intelligence on NetNut's SDKs and backend infrastructure with platform providers and law enforcement 3. NetNut's operator is linked to publicly-traded Israeli firm Alarum Technologies, which rented the residential proxies to cybercriminal and espionage groups 1. The action follows Google's disruption of the IPIDEA proxy network in January. NetNut's reseller and whitelabeling program means several other popular residential proxy brands may run on the same botnet 23.

Analysis
Google's takedown strips NetNut's Google-hosted command-and-control and Play Protect access but leaves the reseller and whitelabeling architecture intact, and independent researchers will likely document NetNut or a rebranded successor sharing its botnet base operating again by October 4. Confidence in that judgment is moderate, given reporting rests on Google Threat Intelligence Group's own disclosure as the sole primary account, with only secondary amplification from outlets like SecurityWeek and BleepingComputer rather than independent verification. The January IPIDEA precedent shows operators buying replacement capacity from competitors rather than shutting down, and GTIG's own count of 316 threat clusters using NetNut's nodes in one week signals demand deep enough to favor reconstitution over collapse, though simultaneous pressure across infrastructure, domains, and Android distribution from Google, the FBI, Lumen, and Shadowserver together could yet prevent the network's rapid return. Confirmation of a resurfacing would force platform providers and ISPs to treat residential-proxy disruption as requiring sustained, coordinated follow-up rather than one-time takedowns.
3 sources
  1. Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices - SecurityWeek
  2. NetNut proxy network disrupted, 2 million infected devices cut off - BleepingComputer
  3. Google's Continued Disruption of Malicious Residential Proxy Networks - Google Cloud Blog (Threat Intelligence Group)

View in full brief →

UNCLASSIFIED // OPEN SOURCE