Google, in coordination with the FBI, Lumen, and other industry partners, has taken action to dismantle the NetNut residential proxy network, also tracked as Popa.
The operation builds on Google’s January 2026 disruption of the IPIDEA proxy network and marks the latest step in the company’s ongoing effort to dismantle malicious residential proxy infrastructure at scale.
As part of this disruption, Google disabled Google accounts and associated services that NetNut used for malware command-and-control (C2), citing direct violations of Google’s Terms of Service and Acceptable Use Policy.
Google Disrupts NetNut Residential Proxy Network
The company also shared technical intelligence on NetNut SDKs and backend C2 infrastructure with platform providers, law enforcement, and research firms to drive broader ecosystem enforcement.
Additionally, Google activated Play Protect to automatically warn users and disable apps bundled with NetNut SDKs, ensuring ongoing protection against future installation attempts.
Google Threat Intelligence Group (GTIG) believes these actions have significantly degraded NetNut’s operations, cutting the operator’s available device pool by millions.
Notably, NetNut runs a reseller program that enables white-labeling, and GTIG has high confidence that several popular residential proxy brands are effectively repackaged NetNut infrastructure.
As seen after the IPIDEA takedown, individual networks often show resilience by absorbing competitors’ capacity and becoming resellers themselves. Google says lasting disruption will require targeting multiple interconnected providers simultaneously, and it plans to continue monitoring how NetNut and its peers adapt.
GTIG estimates the NetNut botnet spans at least 2 million devices worldwide. Public reporting from KrebsOnSecurity, corroborated by Google, shows that NetNut is growing its network by distributing SDKs embedded in common home devices such as smart TVs and streaming boxes.
GTIG has also linked NetNut plugin components to large-scale botnets, including Badbox 2.0. Residential proxy networks let attackers route traffic through legitimate ISP-owned IP addresses, masking malicious activity behind trusted residential infrastructure.
Devices join these networks either through pre-installed malware or hidden proxy code bundled in seemingly legitimate apps. This exposes device owners to serious risk, since their home IPs can be weaponized for hacking and their legitimate traffic may get flagged or blocked by ISPs as a result.

In a single week during June 2026, GTIG tracked 316 distinct threat clusters, spanning cybercriminals and espionage actors, that leveraged suspected NetNut exit nodes to mask their origin IPs during victim access, infrastructure management, and password spray attacks.
Because exit-node traffic traverses the entire home network, compromised devices can also expose other private devices to lateral threats. Research from Synthient, Spur, and Nokia Deepfield has separately documented NetNut’s role in the spread of Mirai DDoS botnet variants.
Google advises users to avoid apps promising payment for “unused bandwidth” or “sharing your internet,” as these are common vectors for proxy network recruitment.
Users should stick to official app stores, scrutinize permissions granted to VPN and proxy apps, and keep Google Play Protect enabled at all times.
When purchasing connected devices like set-top boxes, consumers should verify that they are Play Protect certified by checking Google’s Android TV partner list or following the company’s device verification steps.
Google characterizes this disruption as one step in a longer campaign, noting the residential proxy industry’s rapid growth and the botnet infrastructure’s deep interconnectedness.
The company is calling on mobile platforms, ISPs, and other tech providers to intensify intelligence sharing and take direct action against malicious C2 infrastructure to curb the ecosystem’s long-term expansion.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.