An international effort led by Google, in collaboration with the FBI and several leading cybersecurity players, has severely disrupted NetNut, one of the world's largest residential proxy networks. According to Google's The Threat Intelligence Group (GTIG) estimated the network included at least two million compromised Android devices, including smart TVs and streaming boxes.
NetNut, also known as Popa, has been used by both cybercriminals and state-sponsored spy groups to disguise their identities by routing malicious traffic through the IP addresses of ordinary internet users, allowing attackers to appear as legitimate users when carrying out attacks on organizations and individuals.
Millions of compromised devices were used as proxy servers
According to GTIG, NetNut is estimated to have had control over at least two million infected devices worldwide.
“GTIG estimates that NetNut controls at least two million infected devices globally, including smart TVs and streaming boxes, powered by trojanized applications and botnets like Badbox 2.0 with built-in proxy capabilities.”
However, it is important to distinguish between the infection itself and the proxy network. Devices are infected with malware, such as the Badbox 2.0 botnet or other trojanized applications. NetNut then uses the compromised devices as a global proxy infrastructure where attackers can route their traffic through the victims' internet connections.
How residential proxy networks work
Residential proxy networks rely on consumer devices being hijacked and used as so-called exit nodes. By routing traffic through these devices, cybercriminals can hide their true geographic location and identity behind legitimate IP addresses.
Devices are typically infected through malware that is either pre-installed upon delivery or installed via trojanized apps and other malicious software that the user downloads.

Once a device is compromised, it is used to forward unauthorized network traffic, which can lead to the victim's IP address being classified as suspicious or blocked by ISPs, cloud services, and other digital platforms.
International cooperation hit the infrastructure
The takedown of parts of NetNut was carried out through extensive collaboration between Google, the FBI, Lumen Technologies, The Shadowserver Foundation and several other international cybersecurity partners.
As part of the operation, the FBI seized several domains used by the proxy network, including netnut.com.
Mark Karayan, head of communications at Mandiant, confirmed to BleepingComputer that the .com domain was also used by the NetNut operators along with several other domains that have now been taken down.
Hundreds of threat actors used NetNut
According to GTIG, it was observed for only one week last month 316 different threat clusters who used suspected NetNut exit nodes. These included both cybercriminal groups and state-sponsored espionage actors.
The researchers state that the threat actors used NetNut to:
- anonymously access their own infrastructure
- carry out password injection attacks
- reach compromised environments without revealing the true originating address
- hide malicious activity behind legitimate IP addresses
Google knocked out critical backend infrastructure
In parallel with the international effort, Google shut down the accounts and cloud services that NetNut operators used for their command and control (C2) infrastructure, thereby losing access to a key part of the botnet's backend.
Google also used the built-in security feature Google Play Protect to automatically identify, warn users, and disable infected apps on Android devices.
The company also shared technical indicators, information about NetNut's SDKs, and details about its C2 infrastructure with platform vendors, law enforcement agencies, and cybersecurity researchers to facilitate continued detection and protection.
Could have major consequences for the proxy industry
Google believes that the effort could have far-reaching consequences for the global market for housing proxy services.
One important reason is that NetNut ran an extensive reseller program where other providers could sell the service under their own brands. This means that several popular proxy services were in effect built on NetNut's infrastructure.
According to Mark Karayan, the proxy industry is highly interconnected, with operators continuously buying and reselling capacity from each other's botnets.
“The proxy industry is deeply interconnected, with operators constantly buying and reselling each other’s botnet capacity, and NetNut is one of the world’s largest and most widely used residential proxy networks.”
Important signal for corporate cybersecurity
For businesses, the incident shows how advanced the infrastructure behind today's cyberattacks has become. By using compromised consumer devices, attackers can carry out intrusions, password injection attacks, and fraud from seemingly legitimate Swedish and international IP addresses, making traditional IP-based filtering significantly less effective.
The development underscores the need for modern security solutions that combine identity checks, behavioral analytics, real-time threat intelligence, and continuous monitoring to detect and stop advanced attacks.
Part of Google's long-term strategy
The action against NetNut is part of Google’s long-term effort to disrupt and dismantle proxy botnets that exploit compromised consumer devices. The operation follows previous efforts against the IPIDEA proxy network and marks another step in the effort to disrupt the infrastructure used for cyberattacks, fraud, and digital espionage.
According to Google, the disruption of NetNut is expected to have a broader impact than just the individual network, as several other proxy services build on or resell its infrastructure. For both businesses and individuals, the effort is also a reminder of the importance of only installing apps from trusted sources, keeping Android devices updated, and using security features like Google Play Protect to reduce the risk of becoming part of future botnets.
