A major international operation involving Google, the FBI, and other partners has dismantled the NetNut residential proxy network, which leveraged approximately 2 million compromised devices for malicious activities. The operation represents 1 of the most significant botnet takedowns of 2026.
The NetNut network, also known as Popa, used compromised Android smart TVs, streaming boxes, and other devices to create a massive residential proxy infrastructure. This infrastructure was used by cybercriminals and nation-state actors for malware command and control, anonymization, and other malicious purposes.
What Happened: Google and FBI Dismantle NetNut
The coordinated takedown operation targeted the NetNut proxy network in early July 2026. Google disabled associated accounts and updated Play Protect to remove the malicious applications responsible for compromising devices. The FBI and international law enforcement partners conducted parallel actions against the network's operators.
The operation took down a network that had grown to approximately 2 million compromised devices. These devices were primarily Android-based smart TVs and streaming boxes that had been infected through malicious applications.
Key Details
Residential proxy networks are particularly valuable to threat actors because they route traffic through legitimate home IP addresses. This makes the traffic appear to come from real users, bypassing many security controls designed to detect data center or commercial proxy traffic.
The NetNut network was used for multiple malicious purposes including malware command and control infrastructure, credential stuffing attacks, ad fraud, and anonymization for other criminal activities. The scale of 2 million devices made it 1 of the largest residential proxy networks ever discovered.
Why It Matters
Botnets of this scale cause widespread harm. The compromised devices suffered degraded performance, increased bandwidth usage, and exposure to further compromise. The proxy network enabled a wide range of criminal activities that affected countless victims.
The takedown also demonstrates the effectiveness of public-private partnerships in combating cybercrime. Google's ability to address compromised applications through Play Protect complemented law enforcement actions against the criminal operators.
Industry Context
Botnets have been a persistent problem in cybersecurity. While individual botnets are regularly taken down, new ones emerge continuously. The commoditization of botnet services means that even technically unsophisticated criminals can rent access to large networks of compromised devices.
Smart TVs and IoT devices are increasingly attractive targets for botnet operators. These devices often run outdated software, lack security updates, and are rarely monitored by their owners for signs of compromise.
What It Means for Users and the Industry
For owners of Android smart TVs and streaming devices, the takedown is a reminder to keep software updated and avoid installing applications from untrusted sources. For the security industry, it highlights the importance of monitoring IoT devices for signs of compromise.
For platforms like Google Play, the incident underscores the challenge of preventing malicious applications from reaching devices while maintaining an open ecosystem.
What Happens Next
Google will continue Play Protect updates to prevent reinfection. Law enforcement investigations into the NetNut operators are ongoing. Security researchers expect that new proxy networks will attempt to fill the gap left by this takedown.
Final Takeaway
The NetNut takedown shows that coordinated public-private action can effectively dismantle large-scale botnets. However, the underlying vulnerabilities in IoT device security mean similar networks will continue to emerge.
Residential Proxy Networks
Residential proxy networks like NetNut route traffic through compromised home devices, making the traffic appear to come from legitimate residential IP addresses. This provides anonymity and bypasses security controls that block data center IP ranges. The networks are valuable to cybercriminals for activities including credential stuffing, ad fraud, and hiding command and control infrastructure.
The scale of 2 million compromised devices makes NetNut 1 of the largest residential proxy networks ever discovered. The devices were primarily Android smart TVs and streaming boxes, which are often poorly secured and rarely monitored by owners. Many of these devices were compromised through malicious applications distributed outside official app stores.
The takedown demonstrates the importance of coordinated action between technology companies and law enforcement. Google's ability to address compromised applications through Play Protect complemented the FBI's actions against the criminal operators. This multi-pronged approach is more effective than any single organization's efforts.
FAQs
Sources and Verification
- CybersecurityHunter, July 2026
- Google Security Blog
This article was reviewed as part of CapisTech's editorial fact-checking process.
