
A joint takedown dismantles a botnet of 2 million devices, exposing the hidden economy behind residential IPs and what it means for every household with a connected device.
On July 2, 2026, Google announced a joint takedown of NetNut (also known as Popa)—one of the largest malicious residential proxy networks on the internet. Google's Threat Intelligence Group (GTIG) teamed up with the FBI, Lumen, and other partners to dismantle a network that silently conscripted millions of ordinary home devices into infrastructure rented out to cybercriminals. You can read the full details in Google's threat intelligence blog post.
This is not an isolated event. It follows Google's disruption of the IPIDEA proxy network in January 2026, signaling an ongoing campaign rather than a one-off headline.
What Exactly Is a Residential Proxy Network?
The startling part: the "proxies" being sold are not rented from data center servers but are real IP addresses belonging to real homes—possibly yours—routed through devices sitting in living rooms around the world.
Residential proxy services sell the ability to route internet traffic through IP addresses assigned by ordinary home internet service providers. Because the traffic appears to come from a real home connection, it is much harder to flag as suspicious than traffic from known data centers. That is why it is valuable to bad actors: it lets them mask malicious activity behind the digital fingerprint of an innocent home.
To maintain inventory for such networks, operators need code running on home devices, quietly registering them as "exit nodes." Devices are pulled into the network in one of two ways: either malware is preinstalled before they leave the factory, or their owners unknowingly install an app carrying hidden proxy code. Once enlisted, the device becomes a launch pad for someone else's traffic.
NetNut's Scale
GTIG estimates NetNut involved at least 2 million devices globally, making it one of the largest and most popular residential proxy ip networks in operation. The exact size of such networks is notoriously difficult to pin down, but by any measure the scale here is massive.
How did such a network grow so large? By targeting devices people rarely think of as computers: smart TVs, streaming boxes, and set-top boxes. Reported by KrebsOnSecurity and confirmed by Google, NetNut distributed a software development kit (SDK) designed precisely for such home devices. GTIG also found NetNut plugin components linked to large-scale botnets like Badbox 2.0.
This distribution model has an ugly multiplier effect. Beyond selling access under its own brand, NetNut ran an affiliate program allowing other companies to resell its network under their own labels. Google says it has high confidence that many popular "residential proxy" brands are simply reselling the NetNut botnet underneath.
Why This Should Worry Ordinary Device Owners
If your device is quietly acting as an exit node, the consequences are on you:
- Your home IP becomes cover for attackers. Criminals can route hacks and other unauthorized activity through your address, meaning your legitimate traffic may be flagged as suspicious or blocked outright by your service provider.
- Your home network is exposed. When unauthorized traffic passes through a compromised device, malicious actors may gain access to other private devices on the same network, turning a hijacked streaming box into a gateway to everything else in the house.
And this abuse is not theoretical. In one week in June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. These actors used the network to hide their origin when breaching victim environments and to conduct password spraying attacks. Independent researchers Synthient, Spur, and Nokia Deepfield documented NetNut being used to infect devices with variants of the Mirai DDoS botnet.
What Google Actually Did
Google's fight against NetNut came down to three concrete actions:
- Cut off command and control. Google disabled accounts and services NetNut used for malware command and control (C2), directly violating Google's terms of service and acceptable use policy.
- Shared intelligence widely. GTIG passed technical details about the NetNut SDK and backend C2 infrastructure to platform providers, law enforcement, and research firms, aiming to enforce across the entire ecosystem rather than in a single silo.
- Protected Android users automatically. Google Play Protect now alerts users and disables apps known to bundle the NetNut SDK, and will continue to block future installation attempts.
Google says these combined actions significantly degraded NetNut's network and business, reducing its available device pool by millions.
The Key Problem: The Ecosystem Is Surprisingly Resilient
Here is the sobering takeaway in Google's own assessment. After the IPIDEA takedown, GTIG learned how surprisingly resilient individual networks can be. When operators see their own botnet weakened, they often simply start buying capacity from competitors, becoming resellers themselves. The entire industry is deeply interlinked, built on overlapping botnet armies that are constantly bought and sold.
Meaning one-off point-in-time disruptions, no matter how large, are not a permanent fix. Google defines lasting impact as requiring coordinated pressure on the infrastructure of multiple interconnected providers, and says it will continue to observe how NetNut's peers adapt.
How to Protect Yourself
The practical guidance from the Google team is refreshingly clear:
- Be highly suspicious of apps that pay for "unused bandwidth" or claim to let you "share your network." These are primary recruitment channels for malicious proxy networks and can open real security vulnerabilities in your home network.
- Stick to official app stores and review permissions requested by any third-party VPN or proxy app before installing.
- Keep built-in protections on. Ensure Google Play Protect is enabled on Android devices.
- Buy connected hardware from reputable vendors. For streaming and set-top boxes, Google's Android TV site lists official partners, and you can check if your Android device is Play Protect certified.
The Broader Context
The residential ip industry is rapidly expanding, and Google makes clear this takedown is not the end. Operators rely on shared, resold botnets, making the problem structural rather than limited to a single bad actor. Google calls on mobile platforms, ISPs, and other tech companies to continue sharing intelligence and taking direct action against malicious C2 infrastructure.
For the rest of us, the takeaway is simpler and a bit unsettling: that cheap smart TV or no-name streaming box in the corner is not just a media player. In the wrong supply chain, it can become a rented asset for someone else, worth a second look before it quietly goes to work for them instead.
Comments(0)