FBI Teams Up with Google to Dismantle NetNut Proxy Botnet

2026-07-06 69 0

The FBI, in coordination with the IRS Criminal Investigation Division, executed domain seizures related to NetNut on July 2, replacing the homepage with a federal seizure notice and dismantling one of the largest residential proxy services. The operation was supported by Google, Lumen's Black Lotus Labs, and the Shadowserver Foundation.

What is NetNut?

NetNut is a commercial proxy service provider headquartered in Israel, owned by Nasdaq-listed Alarum Technologies. The company offers residential proxy services, enabling customers to route internet traffic through IP addresses assigned to ordinary households and consumer devices. Businesses typically use such services for web scraping, price monitoring, and ad verification, although the same infrastructure can be abused to conceal malicious activities.

According to Google's Threat Intelligence Group, NetNut's network spanned at least two million devices globally, most of which were Android smart TVs and streaming boxes. These systems acted as exit nodes, making customer traffic appear to originate from ordinary home internet connections rather than data centers or corporate networks.

The company noted that the service has become a common tool for malicious actors. In a single week in June, researchers observed 316 distinct threat clusters using traffic from suspected NetNut exit nodes, involving cybercrime gangs and state-sponsored espionage activities. Specific actions included password spraying, unauthorized access attempts, and communications with attacker-controlled systems.

Residential IPs play a complex role in the internet economy. While legitimate entities use them for business purposes, attackers also value them because these proxies can make suspicious traffic appear as normal consumer behavior. Requests originating from residential IP addresses are less likely to trigger automatic defenses compared to traffic from known abusive hosting providers.

How NetNut Operated

In NetNut's case, devices were integrated into the network through more than one method. Google stated that some products arrived with proxy components pre-installed, while others became part of the system after users downloaded apps containing hidden software development kits. In many cases, device owners were virtually unaware that their internet connection might be used to relay third-party traffic.

Google took a series of technical measures to weaken the network. The company disabled accounts and services associated with NetNut's command infrastructure, shared intelligence about the platform's software and backend systems with industry partners, and updated Play Protect to warn Android users while disabling applications carrying known NetNut components.

Seized Domains

The FBI and IRS seized multiple domains associated with NetNut, including netnut.com, proxyjet.io, and divinetworks.com. The last domain provided static residential proxy services through direct deals with internet service providers. NetNut's .io domain remained online for some time afterward, prompting questions from researchers about the reason.

ANC7

The International Cyber Digest on platform X may have provided an explanation, suggesting that the seized netnut.com domain might have been mistakenly included due to confusion over the use of NetNut's active domains.

The account noted that Internet Archive records for netnut.com did not show it hosting a proxy network service, while netnut.io appeared to indeed be a domain associated with NetNut's proxy product. Hackread.com also verified that netnut.com displayed an advertising banner offering the domain for sale, rather than promoting any proxy-related services.

"The FBI seized netnut(.)com, but Internet Archive does not show that domain ever hosted any proxy network website. The real domain was netnut(.)io," International Cyber Digest tweeted.

ANC8

On the other hand, Alarum acknowledged the enforcement action in a statement issued after the seizure. The company said it would cooperate with investigators and later disclosed that additional domains were affected. It also warned investors that a prolonged disruption of NetNut services could materially impact business operations and financial performance.

NetNut and Its Connection to Popa

Researchers have long noted infrastructure overlaps between NetNut and a botnet called Popa. An investigation by internet watchdog Qurium linked Popa activity to pirated streaming apps, while Google's report showed NetNut-related components appearing in the Kimwolf DDoS botnet and Badbox 2.0 infrastructure.

Although these operations are independent, the overlap illustrates how commercial proxy services and malware networks intertwine. Google had previously dismantled a similar network called IPIDEA in January.

Users should always use proxy IPs for legitimate purposes, purchase connected devices from reputable vendors, check Android products for Play Protect certification, avoid apps that exchange unused bandwidth for money, and review permissions granted to VPN or proxy software. These measures can reduce the likelihood of a TV, streaming box, or other smart device becoming part of someone else's residential proxy network.

Last updated on 2026-07-07 18:13:11

Related Posts

Residential Proxies Under Fire: What Beginners Must Look for When Choosing IPs
Residential IP Selection Guide: 5 Key Dimensions After 2026 Detection Data Su...
2 Million Compromised Devices Blocked: The Residential IP Compliance Storm Ar...
Proxy IP Dirty Pools Trigger Surge in ATO? Review of the July 2026 Attack wit...

Comments(0)

No comments yet

Leave a Comment