Back Streamlinefeed.Co.Ke FBI and Google Dismantle 2-Million Device NetNut Botnet Hijacking Smart TVs
Tech giants and US federal agents have severed the digital spine of a 2-million device botnet, shutting down the NetNut proxy network that hijacked smart TVs.
Tech giants and United States federal agents have severed the digital spine of a massive botnet, shutting down the NetNut proxy network that quietly hijacked millions of household smart televisions globally. The coordinated takedown marks one of the most aggressive maneuvers against cybercriminal infrastructure this decade.
The joint operation, executed by Google's Threat Intelligence Group alongside the Federal Bureau of Investigation (FBI), represents a major escalation in the shadow war against residential proxy networks. For technology regulators across East Africa, including the Communications Authority of Kenya (CAK), the disruption exposes the severe vulnerabilities embedded within cheap, unregulated streaming hardware that floods electronics markets from Nairobi to Lagos. These compromised devices transform ordinary residential internet connections into shields for international espionage and financial fraud.
Operating under the guise of legitimate data routing, the NetNut infrastructure relied heavily on the Popa botnet, a stealth communications layer engineered to evade standard cybersecurity filters. Security researchers confirm that the botnet infiltrated homes through deceptive software development kits (SDKs) bundled into inexpensive, off-brand Android-based smart TVs and unofficial streaming applications. Once plugged into a network, the devices quietly rented out the user's bandwidth to the highest bidder.
The FBI's seizure of hundreds of primary domains, including netnut.com and divinetworks.com, immediately crippled the network's operational capacity. However, Alarum Technologies vehemently disputed the classification of their service as a malicious botnet. In statements issued to financial regulators, the company maintained that users provided consent for bandwidth sharing, though independent cybersecurity audits routinely failed to locate clear, transparent authorization agreements within the infected applications.
The takedown severely impacted the company's stock valuation, sending ripples through the broader proxy reselling market. Google engineers noted that because NetNut operated a robust reseller program, numerous other popular proxy brands were effectively whitelabeling the Popa botnet, meaning the FBI's domain seizures caused cascading failures across multiple supposed competitors.
While the operation originated in Washington and Silicon Valley, the implications reverberate heavily throughout the African continent. Kenya's digital economy, anchored by telecommunications giants like Safaricom, remains uniquely exposed to supply chain vulnerabilities. Millions of unverified Android streaming boxes are imported annually through the Port of Mombasa, largely bypassing rigorous cybersecurity vetting by the Kenya Bureau of Standards (KEBS).
When a Nairobi resident purchases a discounted streaming box to watch the English Premier League, they risk inadvertently incorporating their Wi-Fi into a global cybercrime syndicate. The hijacked bandwidth not only degrades local internet speeds but also subjects the IP address to international blacklists, potentially blocking the user from accessing vital financial portals or government services.
The July 2026 operation did not occur in isolation. It builds directly upon the January 2026 dismantling of the IPIDEA proxy network and the July 2025 disruption of BadBox 2.0. To execute the NetNut takedown, Google disabled associated accounts used for command-and-control infrastructure, preventing the malware from communicating with its central servers. Simultaneously, Google Play Protect was updated to automatically flag and disable applications incorporating NetNut SDKs on certified Android devices.
Despite these victories, federal authorities warn that the residential proxy ecosystem is highly resilient. When operators face the degradation of their own botnets, they historically pivot to purchasing capacity from surviving competitors. The FBI and global cybersecurity coalitions continue to monitor the digital horizon, urging consumers to treat free streaming applications not as harmless entertainment, but as severe security liabilities.
The era of trusting internet-connected household appliances has definitively closed. As cybercriminals increasingly target the living room, international law enforcement is proving that the battleground for global data security now extends directly to the televisions mounted on our walls.
Keep the conversation in one place—threads here stay linked to the story and in the forums.
Sign in to start a discussion
Start a conversation this story and keep it linked here.
E-sports and Gaming Community in Kenya
The Role of Technology in Modern Agriculture (AgriTech)
Popular Recreational Activities Across Counties
Investing in Youth Sports Development Programs
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
