A major international operation involving Google's Threat Intelligence Group, the FBI, Lumen Technologies, and the Shadowserver Foundation has dismantled the NetNut residential proxy network, which leveraged approximately 2 million compromised devices for malicious activities. The operation represents 1 of the most significant botnet takedowns of 2026.
The NetNut network, also known as Popa, used a malicious software development kit embedded in low-cost Android-based smart TVs, streaming boxes, and unofficial apps such as SmartTube to create a massive residential proxy infrastructure. This infrastructure was used by cybercriminals and nation-state actors for malware command and control, anonymization, and other malicious purposes. In just 1 week in June 2026, Google identified at least 316 distinct threat clusters using NetNut's network for password spraying, credential stuffing, advertising fraud, and sensitive data scraping.
What Happened: Google and FBI Dismantle NetNut
The coordinated takedown operation targeted the NetNut proxy network on July 3, 2026. Google disabled associated accounts and updated Play Protect to warn users about and automatically disable apps carrying NetNut's proxy SDK. The FBI, Lumen Technologies, the Shadowserver Foundation, and international law enforcement partners conducted parallel actions against the network's operators.
The operation took down a network that had grown to approximately 2 million compromised devices. These devices were primarily Android-based smart TVs and streaming boxes that had been infected through a malicious SDK bundled into low-cost devices and unofficial apps.
Who Was Behind NetNut
Unlike many botnet takedowns involving anonymous criminal infrastructure, NetNut has a identifiable corporate face: researchers and the FBI's action tie the network to Alarum Technologies, a company publicly listed on the Nasdaq under the ticker ALAR. The FBI's July 2 action seized hundreds of domains associated with the service. Alarum has disputed the allegations, and said that as of its July 3 public disclosure, neither the company nor its NetNut service had been formally contacted by the FBI or any other government or regulatory authority, leaving a notable gap between the law enforcement action and any confirmed direct engagement with the company whose brand is attached to the network.
Key Details
Residential proxy networks are particularly valuable to threat actors because they route traffic through legitimate home IP addresses. This makes the traffic appear to come from real users, bypassing many security controls designed to detect data center or commercial proxy traffic.
The NetNut network was used for multiple malicious purposes including malware command and control infrastructure, credential stuffing attacks, ad fraud, and anonymization for other criminal activities. The scale of 2 million devices made it 1 of the largest residential proxy networks ever discovered.
Residential proxy networks occupy a genuinely gray area in the security industry: legitimate proxy providers sell access to real consumer IP addresses for uses like ad verification, price comparison, and market research, and some obtain that access through consent-based apps that pay users for bandwidth sharing. What separates a legitimate residential proxy business from a case like NetNut is consent and disclosure: whether the device owner actually agreed to have their connection used this way, and whether the SDK bundling that access was transparent about what it did. A malicious SDK quietly embedded in low-cost smart TVs and unofficial streaming apps, with no meaningful disclosure to the device owner, crosses that line regardless of whether the resulting proxy network is technically similar to legitimate commercial offerings.
Why It Matters
Botnets of this scale cause widespread harm. The compromised devices suffered degraded performance, increased bandwidth usage, and exposure to further compromise. The proxy network enabled a wide range of criminal activities that affected countless victims.
The takedown also demonstrates the effectiveness of public-private partnerships in combating cybercrime. Google's ability to address compromised applications through Play Protect complemented law enforcement actions against the criminal operators.
Residential IP addresses are specifically valuable for credential stuffing and password spraying because most account-security systems weight IP reputation heavily when deciding whether a login attempt looks suspicious. A login attempt from a known data-center IP address, the kind commercial VPNs and cloud servers use, gets flagged or rate-limited far more aggressively than the same attempt from what looks like an ordinary home internet connection, since attackers routing traffic through data centers are a well-understood and heavily defended-against pattern. Routing credential-stuffing attempts through two million real residential IP addresses instead lets each individual login attempt blend in with normal traffic from that IP's actual household, which is precisely why a botnet like NetNut is worth far more to a criminal operation than an equivalent number of data-center proxies would be.
Industry Context
Botnets have been a persistent problem in cybersecurity. While individual botnets are regularly taken down, new ones emerge continuously. The commoditization of botnet services means that even technically unsophisticated criminals can rent access to large networks of compromised devices.
Smart TVs and IoT devices are increasingly attractive targets for botnet operators. These devices often run outdated software, lack security updates, and are rarely monitored by their owners for signs of compromise.
What It Means for Users and the Industry
For owners of Android smart TVs and streaming devices, the takedown is a reminder to keep software updated and avoid installing applications from untrusted sources. For the security industry, it highlights the importance of monitoring IoT devices for signs of compromise.
For platforms like Google Play, the incident underscores the challenge of preventing malicious applications from reaching devices while maintaining an open ecosystem.
What Happens Next
Google will continue Play Protect updates to prevent reinfection. Law enforcement investigations into the NetNut operators are ongoing. Security researchers expect that new proxy networks will attempt to fill the gap left by this takedown.
Final Takeaway
The NetNut takedown shows that coordinated public-private action can effectively dismantle large-scale botnets. However, the underlying vulnerabilities in IoT device security mean similar networks will continue to emerge.
Key Points
- In just 1 week in June 2026, Google identified at least 316 distinct threat clusters using NetNut's network for password spraying, credential stuffing, advertising fraud, and sensitive data scraping.
- The operation took down a network that had grown to approximately 2 million compromised devices.
- The coordinated takedown operation targeted the NetNut proxy network on July 3, 2026.
Residential Proxy Networks
Residential proxy networks like NetNut route traffic through compromised home devices, making the traffic appear to come from legitimate residential IP addresses. This provides anonymity and bypasses security controls that block data center IP ranges. The networks are valuable to cybercriminals for activities including credential stuffing, ad fraud, and hiding command and control infrastructure.
The scale of 2 million compromised devices makes NetNut 1 of the largest residential proxy networks ever discovered. The devices were primarily Android smart TVs and streaming boxes, which are often poorly secured and rarely monitored by owners. Many of these devices were compromised through malicious applications distributed outside official app stores.
The takedown demonstrates the importance of coordinated action between technology companies and law enforcement. Google's ability to address compromised applications through Play Protect complemented the FBI's actions against the criminal operators. This multi-pronged approach is more effective than any single organization's efforts.
FAQs
Sources and Verification
- BleepingComputer, July 2026
- The Register, July 3, 2026
- Krebs on Security, Alarum Technologies identification and response
This article was reviewed as part of CapisTech's editorial fact-checking process.



