Skip to content
Google Disrupts NetNut, a 2-Million

Google Disrupts NetNut, a 2-Million

Technadu July 3, 2026

GTIG shared technical intelligence on NetNut's software development kits (SDKs) and backend C2 infrastructure with law enforcement, platform providers, and research firms, and updated Google Play Protect to automatically warn users and disable apps found to contain NetNut SDKs.

Residential proxy networks sell the ability to route traffic through IP addresses owned by internet service providers (ISPs), thereby allowing attackers to hijack them. Device owners’ IP addresses can be used by attackers for hacking and other unauthorized activities, such as password spraying .

When a device becomes an exit node, unauthorized traffic passes through it, exposing other private devices on the same network to internet threats.

NetNut is populated via SDKs distributed on devices like smart TVs and streaming boxes, covertly enrolling them in the malicious network as exit nodes, as per KrebsOnSecurity and others, confirmed by Google.

This is an ongoing campaign of proxy-network disruptions that reveal a pattern rather than an isolated event, and operators facing disruption may simply buy capacity from competitors and resell it to keep operating.

The takedown was coordinated with the FBI, Lumen, and other industry partners, building on Google's January 2026 disruption of the IPIDEA proxy network. GTIG also identified NetNut botnet plugin components tied to the larger Badbox 2.0 botnet , whose operator it sued in July 2025.

Google says it has high confidence that many popular residential proxy brands are white-labeling the NetNut network through its reseller program, so the disruption may not reach every service. Because operators historically respond by buying capacity from competitors, a lasting impact will require targeting several interconnected providers.

NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it, ” Synthient founder Benjamin Brundage has told KrebsOnSecurity.

Google urges consumers to:

Google's findings align with independent public reporting from Synthient , Spur , and Nokia Deepfield , which have documented the use of NetNut to infect devices with variants of Mirai DDoS botnets.

Extracted Entities

Attack Types (3)

Malware (2)

Tools (1)