A man in a black hoodie works on a computer, focused on cyber security.
News

Google and FBI Dismantle NetNut: Inside the Residential Proxy Botnet Used by 316 Threat Clusters to Hide Attack Traffic

Google and FBI disrupted NetNut, a residential proxy botnet of 2 million Android and smart TV devices used by 316 threat clusters for C2 and attacks.
Sami Malik
Copywriter

On 2 July 2026, the FBI seized several domains belonging to NetNut, a residential proxy network that Google's Threat Intelligence Group (GTIG) estimates comprised at least two million compromised devices, primarily Android smart televisions and streaming boxes in private homes. The operation involved Google, the FBI, and Lumen Technologies, and it significantly degraded the network's capacity, removing millions of usable proxy endpoints from the pool available to the threat actors who rented access to them.

The takedown matters beyond its immediate effect on this particular network. NetNut, also tracked by GTIG under the name Popa, is an example of a category of criminal infrastructure that specifically exploits the trust that residential IP addresses carry in security tools and rate-limiting systems. Traffic that appears to originate from a broadband connection in a private home is far less likely to be blocked by Cloudflare protections, email provider IP reputation filters, or corporate VPN detection than traffic from a datacenter. That is precisely the property that makes residential proxy botnets valuable to every category of threat actor from cybercriminal credential stuffers to nation-state espionage groups.

What NetNut Did and How It Operated

NetNut sold access to its pool of residential proxy endpoints through a commercial interface. Customers, which GTIG found to include 316 distinct threat clusters in a single week in June 2026, paid to route their attack traffic through exit nodes that appeared to originate from ordinary home internet connections. The traffic those customers routed included password-spraying attacks against Microsoft 365 tenants, credential stuffing campaigns, command-and-control communications from malware operators who needed to hide their infrastructure's real origin, and web scraping at scales that would trigger datacenter IP blocks.

The devices in the NetNut pool were not consciously participating. They were ordinary consumer devices, smart televisions, Android streaming sticks, and set-top boxes, that had been compromised through malicious applications available on third-party app stores or through app supply-chain attacks. Once the malicious application ran on the device, it enrolled the device in the proxy network, which then rented the device's bandwidth and internet connection to paying customers. The device owner's home internet address became part of the criminal infrastructure. If an attacker routed a credential-stuffing campaign through someone's living room television, that television's IP address appeared in the logs of the targeted service, not the attacker's actual machine.

The Scale of Threat Actor Use

The 316 distinct threat clusters GTIG counted using NetNut exit nodes in a single week represents a striking diversity of actors. GTIG's assessment covered both financially motivated cybercriminal groups and espionage-focused state-linked actors. Credential-theft campaigns, ransomware affiliate infrastructure, phishing operations, and nation-state reconnaissance all shared the same pool of residential exit nodes, each cluster routing different kinds of malicious traffic through the same ordinary home connections.

This co-mingling of threat actors on shared infrastructure is characteristic of the residential proxy market. From the network operator's perspective, traffic is traffic. From a defender's perspective, it means that blocking a NetNut exit node IP would affect a password-spraying operation targeting one company, a phishing campaign targeting another, and a ransomware operator's C2 traffic all at once. The IP alone carries no actor attribution.

For security operations teams trying to investigate alerts, traffic from residential proxy pools creates a specific challenge: IP-based attribution is entirely unreliable. The geolocation of an exit node IP may point to a suburb in Ohio or a flat in Manchester, while the actual attacker is in a different country entirely. Behavioural signals in the traffic itself, the timing patterns, the request structure, the user agent strings, carry more investigative value than the source IP when residential proxies are involved.

Who Owns NetNut and Why That Matters

What distinguishes NetNut from purely criminal botnet infrastructure is that it traces back to a legitimate, publicly traded company. NetNut is operated by a subsidiary of Alarum Technologies, a company listed on the NASDAQ exchange under the ticker ALAR. Alarum positions NetNut publicly as an ethical residential proxy service, claiming that all devices in its network have consented to participate.

GTIG's investigation found that a meaningful portion of the two million devices in the network had not, in any meaningful sense, opted in. They were compromised devices enrolled through malicious applications, not through informed consent. This gap between the company's public positioning and the reality of how a significant portion of its network was built is at the centre of the legal and regulatory questions the FBI action raises.

The existence of publicly traded companies with legitimate business registration as the operators of residential proxy networks used by criminal and espionage actors is a structural problem that takedowns of specific domains do not fully address. The disruption degrades the network's current capacity, but the business and its commercial relationships continue.

What This Means for Defenders

The NetNut operation illustrates why residential IP reputation is not a reliable indicator of traffic legitimacy. Security tools that use IP reputation as a primary signal for distinguishing legitimate from malicious traffic are poorly calibrated for an environment where two million residential IPs, distributed across dozens of countries, are available to threat actors on demand. Rate limiting by IP, geographic blocking that relies on residential IPs being trusted domestic sources, and login attempt monitoring that uses IP reputation to prioritise alerts are all affected.

The credential-stuffing and password-spraying traffic that GTIG counted routing through NetNut nodes is the kind of traffic that produces successful account takeovers when it hits accounts with weak or reused passwords. Those compromised accounts, and the credentials that made them vulnerable, often originate from earlier data breaches. Understanding which of your organisation's credentials are already in breach data sets is part of understanding the realistic threat surface for credential-stuffing attacks routed through residential proxies. Monitoring for credential exposure is one of the few ways to get ahead of an attack that is designed to look like legitimate traffic from a residential connection.

The Continuing Residential Proxy Problem

NetNut is one of several residential proxy networks operating at scale. GTIG has published research on similar networks before the NetNut action and will encounter more. The FBI seizure disrupts this particular network's current infrastructure, but the commercial model that supports it persists. Criminal actors who used NetNut will migrate to alternative networks in the period following the seizure.

For defenders, the implication is not that residential proxy takedowns are ineffective, they impose real costs on threat actors and disrupt ongoing campaigns, but that the disruption is temporary and the infrastructure category will continue to exist. The controls that protect against credential attacks routed through residential proxies, strong unique credentials, phishing-resistant MFA, and monitoring for leaked credential data, are durable regardless of which proxy network attackers use next. Disruptions to criminal infrastructure buy time. Defensive capability is what uses that time productively.

Residential Proxy Networks and the Attribution Problem They Create

The NetNut takedown provides a useful lens for examining a structural problem in cybersecurity attribution and threat intelligence: when attackers route traffic through residential IP addresses, the IP address itself stops being a reliable indicator of malicious activity. Security tools, threat intelligence feeds, and SIEM rules that use IP reputation as a primary signal are systematically disadvantaged when residential proxy pools are in play.

GTIG counted 316 distinct threat clusters using NetNut in a single week. Those 316 clusters generated traffic from what appeared to be millions of distinct residential IP addresses scattered across dozens of countries. A SIEM rule that flags authentication attempts from datacenter IP ranges, or that applies higher risk scores to logins from known hosting provider ASNs, would not have flagged traffic routed through a NetNut Android TV in suburban Ohio. The residential IP carries none of the datacenter reputation signals that such rules rely on.

This is not a new problem, but the scale of the residential proxy market has grown considerably. Google's research on NetNut places it as one of the largest such networks, but it is far from the only one. Security teams that have built detection logic around IP reputation signals should understand that those signals are increasingly unreliable for detecting attacks that route through residential proxy infrastructure. Behavioural signals, the timing of requests, the volume of authentication attempts, the request structure and user agent strings, carry more discriminating power in this environment than source IP reputation.

For organisations that saw their IP addresses flagged as sources of malicious traffic during the NetNut operation, the experience is a concrete demonstration of how residential proxy infrastructure affects ordinary users and businesses. A home user with a compromised Android TV streaming box may find their home IP address on threat intelligence block lists because attackers routed credential-stuffing attempts through their device. Removing that block-listing once the device is cleaned or replaced requires contacting each threat intelligence provider separately, a process that is not fast.

The Alarum Technologies angle, a NASDAQ-listed company as the operator of a network that GTIG found hosting 316 criminal threat clusters, raises broader questions about the accountability of commercial infrastructure that enables criminal use even when the operator claims not to intend it. The legal and regulatory frameworks for holding commercial proxy providers accountable for the use of their infrastructure are less developed than the frameworks for, say, bulletproof hosting providers that operate explicitly for criminal customers. The NetNut case, with an ongoing FBI involvement and a publicly traded operator, may produce legal precedents that shape that accountability landscape.

For the organisations whose Microsoft 365 environments were targeted by password-spraying campaigns routed through NetNut infrastructure, the immediate outcome of the takedown is that a significant source of the residential exit nodes that made those campaigns harder to block has been disrupted. But the credential data used in those campaigns, the usernames and passwords from earlier breaches, still exists in criminal hands. The disruption to the routing infrastructure does not expire or invalidate the credential lists. New proxy infrastructure will emerge to replace NetNut's capacity. The credential exposure that makes those campaigns dangerous persists independently of any takedown, and addressing it requires identifying and rotating the exposed credentials before attackers use the next available proxy pool to test them again.

How Residential Proxy Networks Are Built and Sustained

Understanding how residential proxy networks like NetNut acquire and maintain their device pools helps defenders assess the ongoing risk even after a takedown. Devices are enrolled through several mechanisms. The most common in the NetNut case was malicious applications distributed through third-party Android app stores, platforms outside the Google Play Store where security review is absent or minimal. These applications appear to offer legitimate utility, media players, VPN clients, download managers, while embedding background services that enrol the device in the proxy network and route traffic through it when the device is idle.

A second mechanism involves supply-chain attacks on legitimate application updates. A developer whose application is acquired or whose build pipeline is compromised can push a malicious update to existing users who have already installed and trusted the application. This mechanism is harder to detect at the device level because the application's installation source is legitimate, and the update is signed with the developer's certificate.

A third mechanism specific to smart television and streaming device ecosystems is the pre-installation of proxy software at the firmware level by OEM manufacturers with questionable supply chains. Devices sold through low-price-point channels, particularly from manufacturers with limited security review, have been found to ship with proxy network software embedded in firmware that persists through factory resets. For organisations that have these devices on corporate networks or that allow them on networks adjacent to sensitive systems, firmware-level proxy software is difficult to detect and impossible to remove without replacing the device.

Once enrolled, the device's connection to the proxy network typically runs as a background process that activates during idle periods, most commonly overnight or during television standby mode. The bandwidth consumption is usually limited to avoid detection through unusually high data usage, and the traffic is often compressed and encrypted to prevent the device owner or their ISP from identifying its nature through inspection. Devices remain in the pool until they are factory-reset, their internet connection changes in a way that makes them unreachable, or an intervention like the NetNut operation disrupts the coordination infrastructure.

The FBI's Domain Seizure: What It Does and Does Not Accomplish

The FBI's seizure of NetNut domains on 2 July 2026 disrupted the coordination infrastructure that the proxy network uses to direct traffic to enrolled devices and return it to paying customers. When a threat actor rents access to a NetNut exit node, their traffic request passes through NetNut's infrastructure, which routes it to an enrolled device, which forwards it through the device's home internet connection. Seizing the coordination domains breaks this routing step: the infrastructure that directs traffic to specific enrolled devices becomes unreachable, and existing enrolled devices cannot be given instructions or receive traffic routing through the seized infrastructure.

The enrolled devices themselves are not removed from the network by the domain seizure. The two million Android televisions and streaming boxes with the proxy software installed continue to have that software on them. If the proxy network operator spins up replacement infrastructure with new domains, those devices can be contacted at next activation and reconnected. The takedown degrades the network's capacity during the period when the operator is rebuilding coordination infrastructure, but it does not permanently decommission the enrolled device pool unless those devices are cleaned individually.

The Lumen component of the takedown, which disrupted the traffic routing at the network infrastructure level, provides a more durable disruption because it operates at a layer that does not depend on devices contacting specific domains. Lumen's involvement in previous botnet disruptions has included null-routing traffic to and from known botnet infrastructure at the IP level, which prevents enrolled devices from communicating with operator infrastructure regardless of what domain names are resolved. This layer of the disruption persists beyond a domain seizure because it operates on IP addresses rather than DNS names, and IP changes are more expensive for operators to cycle through than domain registrations.

Practical Steps for Organisations After the NetNut Disruption

Organisations whose security tools flagged elevated attack traffic from residential IP addresses in the weeks before the NetNut takedown should review those logs with the understanding that some of the traffic may have been routed through NetNut exit nodes. Identifying the specific IPs and correlating them against GTIG's published NetNut infrastructure indicators can help determine whether the traffic was part of a NetNut-routed campaign. If the traffic included successful authentications or successful exploitation, the subsequent investigation scope is shaped by what the attacker did after gaining access rather than by the IP address they appeared to come from.

For organisations that operate IoT or smart television devices on corporate or guest networks, reviewing those devices for proxy network software is worth adding to the next scheduled asset inventory cycle. Android-based smart televisions can be inspected for unexpected background applications through the device's application management settings, though firmware-level proxy software may not appear in the standard application list. Where IoT devices are present on network segments adjacent to sensitive systems, ensuring that network segmentation prevents IoT devices from reaching corporate resources is the practical control that limits the blast radius if a device is found to be enrolled in a proxy network.

Checking Whether Your Devices Are in a Proxy Pool

Home users and organisations with smart television or streaming devices on their networks can look for signs that a device has been enrolled in a proxy network by monitoring the device's network traffic. Unusual outbound connections to unfamiliar IP addresses during periods when the device is nominally idle, or data usage that is unexpectedly high despite limited active viewing, are potential indicators. On Android-based smart TVs, reviewing the list of installed applications and looking for services with vague names that have no obvious function, combined with unusually broad network permissions, can surface proxy network applications. For corporate environments, network monitoring that flags consumer IoT devices making connections to known proxy network infrastructure IP ranges provides a more reliable detection capability than device-level inspection.

How Defendis Helps Organisations Respond to Credential and Identity Exposure

The attacks described in this article share a common thread: every one of them either harvests credentials, abuses legitimate identity infrastructure, or exploits the gap between patching timelines and attacker speed. GhostLock and wp2shell give an attacker on an internal machine or a compromised web server a direct route to deeper access. Helix bypasses MFA entirely by abusing Microsoft's own OAuth flows. NetNut makes attribution nearly impossible by routing attack traffic through ordinary home connections.

Defendis monitors the dark web, criminal forums, and breach indices for credentials and data linked to your organisation. When an attacker uses leaked credentials to pivot into your environment, or when data extracted from a compromised system surfaces for sale, Defendis surfaces the exposure with full context so your security team can act before damage compounds.

Book a demo to see how Defendis approaches dark web monitoring for enterprise security teams.

About the author
Sami Malik is a copywriter passionate about crafting clear, engaging, and impactful content that helps brands connect with their audience through storytelling and strategy.

Related Articles

Discover simplified
Cyber Risk Management
Learn how to prevent cyberattacks proactively with a free trial of Defendis.