NetNut Proxy Network Dismantled, 2 Million Infected Devices Cut Off

A global law enforcement and industry operation has severed the NetNut proxy botnet, closing a major enabler of cybercrime and espionage.

By Central
The NetNut botnet used at least 2 million compromised Android devices to anonymize malicious traffic, with Google's Play Protect blocking infected apps.
Highlights
  • The NetNut botnet compromised over 2 million Android devices, including smart TVs and streaming boxes, to create a residential proxy network.
  • Google, the FBI, and industry partners like Lumen Technologies and The Shadowserver Foundation collaborated to take down the botnet.
  • Google used Play Protect to automatically disable infected apps on Android devices, and shared technical data to prevent future abuse.

A coordinated law enforcement and industry operation has dismantled NetNut, a sprawling residential proxy network that weaponized at least two million compromised Android devices — including smart televisions and streaming boxes — to conceal cybercriminal and espionage traffic behind legitimate home internet addresses. Known internally as Popa, the botnet provided hundreds of threat actors with a vast pool of residential IP addresses, making their attacks far harder to trace and block.

How the NetNut Residential Proxy Botnet Operated

Residential proxy networks like NetNut function by infecting everyday consumer devices and then selling access to those compromised systems. Attackers route their malicious traffic through the victims’ home IP addresses, which appear legitimate to online services and fraud-detection systems. Devices typically become part of the botnet through malware pre-installed before purchase or via trojanized applications that users download themselves. Once infected, these devices act as exit nodes, forwarding unauthorized traffic and potentially causing the victim’s IP address to be flagged or blocked by internet service providers.

Scale of the Infection: At Least 2 Million Devices

According to the Google Threat Intelligence Group (GTIG), NetNut controlled no fewer than two million infected devices globally, a figure that includes smart TVs and streaming boxes. The botnet’s reach was powered by trojanized applications and other botnets such as Badbox 2.0, which package proxy plugins that silently enroll devices into the network. GTIG reported that in a single week last month, it observed 316 distinct threat clusters using suspected NetNut exit nodes, encompassing both cybercriminal operations and espionage groups.

Coordinated Disruption: Google, FBI, and Industry Partners

The takedown was the result of a joint effort involving Google, the Federal Bureau of Investigation, Lumen Technologies, The Shadowserver Foundation, and other industry partners. A key component of the operation was the seizure of the netnut.com domain by the FBI. Mandiant confirmed that this domain, along with others, was actively used by the proxy service. Google simultaneously disabled the accounts and infrastructure on its own platforms that NetNut operators relied on for command-and-control (C2) operations, effectively severing access to the botnet’s critical backend systems.

Protecting Users Through Google Play Protect

Google also took direct action to protect end users by automatically triggering warnings and disabling infected applications through Google Play Protect, Android’s built-in security mechanism. Beyond these user-facing protections, Google shared detailed technical information about NetNut’s software development kits (SDKs) and backend C2 infrastructure with platform providers, law enforcement agencies, and cybersecurity researchers worldwide.

Broader Implications for the Proxy Industry

The disruption of NetNut is expected to send ripples through the residential proxy industry. GTIG noted that the botnet operated a robust reseller program, allowing other services to whitelabel its network, meaning many popular residential proxy offerings were effectively fueled by NetNut. Mandiant observed that disrupting a single proxy service often forces operators to purchase replacement capacity from competing providers, who then effectively become resellers of the same underlying compromised infrastructure. This action follows Google’s earlier disruption of the IPIDEA residential proxy network earlier this year, signaling a sustained campaign against this category of threat.

What Affected Users Should Do Now

Anyone who suspects their Android device — particularly a smart TV or streaming box — may have been part of the NetNut botnet should take immediate steps to secure their home network. Check for any unfamiliar or suspicious applications installed on your devices and remove them. Run a full scan using a reputable mobile security application that offers real-time threat detection. Change the passwords associated with any online accounts accessed from an affected home network, and enable two-factor authentication wherever possible. If you use public Wi-Fi, protect your traffic with a VPN service that employs AES-256 encryption and includes a kill switch. Finally, ensure all your devices are running the latest available firmware and operating system updates to patch known vulnerabilities that botnets like NetNut routinely exploit.

Share This Article