Back Techtimes FBI and Google Disrupt NetNut Botnet That Rented 2 Million Home Devices to Spies
The smart TV or streaming box sitting in your living room may have spent the past several years quietly renting your internet connection to hackers, password-spraying crews, and government espionage groups — without your knowledge, without your consent, and at no benefit to you whatsoever. That ended Thursday, at least in part, when the FBI and Google jointly dismantled NetNut, one of the largest residential proxy botnets ever documented, which had secretly enrolled an estimated 2 million consumer devices and served 316 distinct cybercriminal and espionage clusters in a single week this June.
The coordinated disruption — executed by Google's Threat Intelligence Group (GTIG) alongside the FBI, Lumen Technologies, the Shadowserver Foundation, and the IRS Criminal Investigation division — struck the network from three directions at once: cutting off the Google accounts and services NetNut used for command-and-control, sharing technical intelligence NetNut's hidden software development kits (SDKs) with platform providers and security researchers worldwide, and updating Google Play Protect to automatically detect, disable, and block any Android application known to contain NetNut's proxy code. The FBI simultaneously seized hundreds of domains, including netnut.com, proxyjet.io, and divinetworks.com, replacing the NetNut homepage with a federal seizure banner.
NetNut, also tracked by researchers under the name "Popa," is a residential proxy network operated by Alarum Technologies, an Israeli company publicly listed on the Nasdaq exchange (ticker: ALAR). On the surface, residential proxy services market themselves as tools for businesses to route web traffic through real household IP addresses — used for ad verification, price monitoring, and web scraping. But a residential proxy network requires millions of real devices to function as exit nodes, and the way NetNut built that pool of devices is what drew federal law enforcement.
GTIG, along with independent security firms including Synthient, Qurium Media Foundation, Nokia Deepfield, and Spur Intelligence, documented that NetNut populated its botnet by distributing SDKs embedded in ordinary-looking applications — primarily IPTV apps, streaming utilities, and tools offered to consumers who own smart TVs and Android streaming boxes. These SDKs did not announce their true function. Synthient examined more than 20 apps known to contain the NetNut proxy code and found that not one presented users with a meaningful consent prompt explaining that installing the app would turn their internet connection into a relay for paying strangers.
Once an app carrying the SDK was installed, the device was silently enrolled. The SDK established a background connection to NetNut's command-and-control infrastructure — infrastructure that, GTIG found, was hosted on Google's own services, a technique known as "living off trusted services" that hides malicious traffic inside ordinary cloud-provider network flows. The SDK then opened a local proxy listener port, configuring the device as an exit node for NetNut's paying customers.
The commercial value of residential proxies — and the danger they represent — comes down to a technical fact how the internet identifies traffic. IP addresses assigned by consumer internet service providers carry high trust scores in commercial anti-bot, fraud detection, and security systems, because those addresses belong to ISP Autonomous System Numbers (ASNs) with long provenance trails in public IP reputation databases. A request originating from a ISP IP looks indistinguishable from an ordinary consumer browsing the web. A request from a datacenter IP is trivially identifiable as commercial or potentially automated infrastructure and is routinely blocked or scrutinized.
In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes. Those clusters included both organized cybercriminal gangs and nation-state espionage groups, which used the network to mask their real locations when accessing victim environments, reaching their own infrastructure, and launching password spray attacks against corporate targets. GTIG's NetNut disruption report
The danger to device owners did not stop at slow internet or a flagged IP address. When a consumer device functions as an exit node, unauthorized traffic from paying NetNut customers does not stay neatly contained to that device. It passes through it — and because the device is on the network alongside laptops, phones, smart speakers, and security cameras, that traffic opens a path to every other device behind the same router.
GTIG stated this plainly: bad actors using NetNut could access other private devices on the same network, effectively exposing them to internet threats. The network segment that most consumers treat as a trusted, protected environment was, for the owners of enrolled devices, exposed to whatever NetNut's paying customers chose to do with their access. Synthient's research on network exposure
Public reports by Synthient, Spur, Nokia Deepfield, and others also documented that NetNut infrastructure was used to infect enrolled devices with variants of the Mirai malware family — the same class of malware responsible for some of the largest distributed denial-of-service attacks in internet history — compounding the risk beyond passive traffic relaying.
GTIG described its actions in three parts, each targeting a different layer of NetNut's operation.
Second, Google shared detailed technical intelligence NetNut's SDKs and backend C2 infrastructure with platform providers, law enforcement agencies, and security research organizations — aiming for ecosystem-wide enforcement rather than a single point-in-time disruption limited to Google's own platforms.
Third, Google Play Protect — Android's built-in malware defense — was updated to automatically warn users and disable applications known to incorporate NetNut SDKs, with protections extended to block future install attempts. Android users on certified devices who have Play Protect enabled received or will receive alerts affected applications.
Simultaneously, the FBI executed seizure warrants targeting hundreds of NetNut-associated domains. The agency was joined in the seizure banner by the IRS Criminal Investigation division, a collaboration that suggests the investigation may extend to financial crime allegations alongside the network-abuse charges.
Alarum Technologies' legal counsel, Omer Weiss, confirmed the company was aware of the domain seizures and said Alarum would "fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account." The company has in prior statements disputed the characterization of its software as a botnet, describing independent security research findings as "demonstrably inaccurate assertions and flawed deductions." Those prior denials stand in conflict with the independent technical finding, documented by Synthient across more than 20 examined applications, that the SDK was deployed without presenting users any meaningful consent prompt.
Google was direct the limits of what Thursday's action achieved — and those limits say something important the residential proxy industry that consumers and security professionals alike need to understand.
After Google disrupted IPIDEA, NetNut's largest competitor, in January 2026, the outcome was instructive. Research by Bitsight found that IPIDEA's successor infrastructure rebuilt to pre-disruption device counts within a single day. The mechanism is straightforward: proxy operators who lose their own botnet capacity simply purchase access from competitors, effectively becoming resellers. The underlying market demand does not disappear; it migrates. When there are multiple large, interconnected residential proxy networks — all drawing from overlapping pools of hijacked consumer devices, all connected through reseller programs — taking down one provider degrades the market but does not restructure it.
NetNut's reseller program made this problem acutely visible. GTIG stated it has "high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet" — meaning many proxy services that appear to consumers and enterprise buyers to be independent products were drawing from the same pool of your hijacked devices. The disruption of NetNut therefore carries downstream consequences across the residential proxy industry, even for services that do not bear the NetNut name. But it does not dismantle the market's structural capacity to reconstitute.
GTIG acknowledged this explicitly: "We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers." The company said it intends to continue monitoring how NetNut's peers adapt to the action and plans additional enforcement campaigns targeting related operators. Bitsight's residential proxy market resilience research
GTIG's consumer guidance addresses what individual users can do right now, and it is more specific than the usual advice to "keep devices updated."
The primary recruitment mechanism for residential proxy botnets is applications that offer payment in exchange for "sharing your unused bandwidth" or "letting your internet connection work for you while you sleep." These offers should be treated as an unambiguous warning sign. No legitimate application that genuinely respects user consent needs to monetize your internet connection in the background.
For Android devices and Android TV devices specifically, enabling and keeping Google Play Protect active is the most direct mitigation. Play Protect is now configured to automatically disable applications known to contain NetNut SDKs and to block future install attempts from the same sources. Users can verify Play Protect status by opening the Google Play Store, navigating to the , selecting "Play Protect," and confirming it shows as active.
For anyone purchasing a streaming box, set-top box, or smart TV, GTIG advised choosing hardware from manufacturers on Google's Android TV partner list, available at android.com/tv. Devices bearing Android TV certification run the official OS build with Play Protect integration; uncertified devices — typically sold at steep discounts through online marketplaces — often run unofficial Android variants without these protections and have historically been primary Popa/NetNut recruitment targets.
Readers who want to check whether their IP has been observed functioning as a residential proxy node can use Synthient's IP-check tool . This does not identify which specific device on a network is enrolled, but it can confirm whether the household IP has been flagged.
A traditional botnet uses compromised devices to launch attacks directly — flooding targets with traffic, sending spam, or stealing data. A residential proxy botnet does something economically distinct: it rents out the compromised devices' internet connections to paying customers who use them to disguise their own traffic. The customers get IP addresses that look like ordinary households, which lets them bypass security filters that block datacenter or commercial hosting IPs. For the botnet operator, the business model is persistent revenue from selling access rather than one-time attacks. For device owners, the result is that their internet connection is being commercially exploited, their IP address may be flagged by their ISP or appear in law enforcement records, and every other device on their network is exposed to whoever is using that exit node at any given moment.
There is no simple in-device indicator. On Android-based devices, the most effective step is to open the Google Play Store, go to Play Protect, and run a scan — Play Protect now flags and disables apps known to contain the NetNut SDK. If you installed an app that offered to pay you for "sharing unused bandwidth" or "letting your internet work for you," uninstall it immediately. You can also visit Synthient's IP-check tool to see whether your IP address has been observed functioning as a proxy node. For a deeper check, review any IPTV or streaming utility apps on your device against a list of apps flagged in GTIG's published research — specifically any application that requests permissions to run persistently in the background with network access.
Because the problem is a market, not a single operator. The residential proxy industry connects multiple large networks through reseller programs; when one network is disrupted, paying customers migrate to competitors, often within hours. After Google disrupted IPIDEA — NetNut's largest competitor — in January 2026, Bitsight found that successor infrastructure rebuilt to pre-disruption device counts within a single day. NetNut itself ran a "whitelabeling" reseller program that Google says with high confidence powered many seemingly independent proxy brands. Those downstream resellers continue to exist, and some may now be purchasing capacity from other providers. The structural problem — millions of consumer devices enrolled as proxy exit nodes through hidden SDKs in apps — persists until app stores, device manufacturers, and ISPs coordinate enforcement at a level that addresses the underlying SDK distribution chain, not just individual network operators.
Check whether the device is on Google's official Android TV partner list at android.com/tv before purchasing. Devices on this list run the certified Android TV operating system, which includes Google Play Protect integration and gives Google the technical ability to push SDK-detection updates. Uncertified Android devices — common in budget streaming boxes sold on online marketplaces — run unofficial OS variants without this protection and have been the primary recruitment targets for the Popa/NetNut botnet. Price is not a reliable safety indicator in either direction, but devices sold significantly below the market rate for comparable certified hardware should prompt additional scrutiny. Once you own a device, avoid any application that offers payment for internet sharing, review permissions on all installed streaming and IPTV apps, and keep Play Protect active and updated.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
