Cybercrime

Google and FBI dismantle Residential Proxy Network Built on Millions of Hijacked Home Devices

Google and FBI dismantle Residential Proxy Network Built on Millions of Hijacked Home Devices

Google announced on July 2, 2026 that it has taken coordinated action against NetNut, a residential proxy network also tracked as Popa. According to Google Threat Intelligence Group (GTIG), the operation was carried out alongside the FBI, Lumen, and other partners, and follows the company's January 2026 disruption of the IPIDEA proxy network.

The action had three parts, according to the company. Google disabled accounts and services that NetNut allegedly used for malware command and control (C2), citing violations of its Terms of Service and Acceptable Use Policy. It shared technical intelligence on NetNut software development kits (SDKs) and backend C2 infrastructure with platform providers, law enforcement, and research firms. And it set Google Play Protect, Android's built-in security layer, to warn users and disable apps known to carry NetNut SDKs, with continued blocking of future install attempts.

Google believes the combined measures significantly degraded NetNut's network and business, reducing the pool of devices available to the operator by millions. NetNut had not publicly responded in the material reviewed for this story.

Over 2 million devices

GTIG estimates NetNut controls at least 2 million devices worldwide, while cautioning that sizing residential proxy networks is extremely difficult. Reporting by KrebsOnSecurity, which Google says it confirmed, documented how the network seeds itself through SDKs embedded in common household hardware such as smart TVs and streaming boxes. Devices end up enrolled either because malware is pre-installed before purchase or because users unknowingly download apps carrying hidden proxy code. GTIG says it has also identified NetNut plugin components inside large-scale botnets, including Badbox 2.0.

Why it matters

Residential proxy networks sell the ability to route traffic through IP addresses that belong to ordinary internet service provider customers. For attackers, that means intrusions, credential attacks, and infrastructure access all appear to come from normal homes rather than suspicious hosting providers.

The scale of abuse is the striking number in Google's post. In a single week in June 2026, GTIG observed 316 distinct threat clusters, spanning cybercriminal and espionage groups, using suspected NetNut exit nodes for activity including password spray attacks and masking their origin when touching victim environments.

When a consumer device becomes an exit node, unauthorized traffic flows through the owner's home connection, their IP can be flagged or blocked by service providers, and other devices on the same network are exposed. Researchers at Synthient, Spur, and Nokia Deepfield have documented NetNut being used to infect devices with variants of the Mirai DDoS botnet, according to Google.

Perhaps the most consequential claim is about the market itself. Google says it has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet through the operator's reseller program. And after the IPIDEA takedown, Google observed that operators facing degradation simply buy capacity from competitors, effectively becoming resellers themselves. In Google's view, lasting disruption requires hitting several interconnected providers rather than one network at a time.



International Cyber Digest

Get the ICD Newsletter

Subscribe for source-forward cyber news, OSINT notes, breach updates, and analysis. Have evidence or a lead? Send it to ICD.

Subscribe Send a tip