Google has announced a major cybersecurity operation targeting NetNut, one of the world’s largest residential proxy networks. The action was carried out with support from the FBI, Lumen Technologies, and several industry partners. According to Google’s Threat Intelligence Group (GTIG), the operation has significantly reduced NetNut’s ability to use compromised home devices across the world. The company estimates that the network relied on at least two million internet-connected devices.

NetNut, also known as Popa, works by turning ordinary consumer devices into proxy servers without most users realizing it. These devices include smart TVs, streaming boxes, and other internet-connected products found in homes. Once a device becomes part of the network, other people can route their internet traffic through that home’s connection. This makes malicious activity appear to come from an innocent user’s internet address instead of the real attacker.
Google explained that residential proxy networks are often used to hide the true source of online activity. While this technology has legitimate business uses, cybercriminals frequently abuse it to avoid detection during attacks. GTIG observed 316 separate cybercrime and espionage groups using suspected NetNut exit nodes in just one week during June. Some of these groups reportedly used the network to carry out password-spraying and other malicious operations.

To weaken the network, Google disabled Google accounts and services that were being used for NetNut’s malware command-and-control operations. The company also shared technical intelligence about NetNut’s infrastructure, software development kits (SDKs), and backend systems with law enforcement agencies, platform providers, and cybersecurity researchers. Google believes these coordinated efforts have reduced the number of usable devices available to the network by millions.
Google has also strengthened Android security by updating Play Protect to detect and disable applications known to contain the NetNut SDK. According to the company, some devices become part of the network because proxy software is pre-installed on low-cost hardware, while others are infected through free apps that secretly include the SDK. Once installed, the software allows outside traffic to enter the home network, increasing security risks for users.

Researchers also warned that residential proxy services can expose home networks to additional threats. Because outside traffic passes through an infected device, attackers may gain opportunities to target other connected devices on the same network. Google noted that some of these compromised devices have previously been linked to large botnets such as Mirai and BadBox 2.0, showing how proxy networks and malware campaigns can overlap.
Investigations by multiple security researchers have linked the Popa network to NetNut, a residential proxy provider owned by Israeli company Alarum Technologies. In response, Alarum confirmed that the FBI had seized certain domains associated with NetNut. The company stated that it takes the matter seriously and will fully cooperate with law enforcement to investigate any misuse of its infrastructure and help identify those responsible.

Google believes the impact of this operation could extend beyond NetNut because many residential proxy providers operate through reseller or white-label programs. The company says several well-known proxy brands may rely on the same underlying infrastructure. Google is also urging users to avoid apps that promise payments for sharing unused internet bandwidth and to purchase connected devices only from trusted manufacturers, helping reduce the risk of unknowingly becoming part of malicious proxy networks.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news