A massive residential proxy network just got taken down. NetNut — also known as Popa — gave cybercriminals and espionage groups access to over two million compromised Android devices. Smart TVs, streaming boxes, phones. All of them were being used as cover for attacks.
Google’s Threat Intelligence Group (GTIG) led the charge alongside the FBI, Lumen Technologies, and The Shadowserver Foundation. The FBI seized NetNut’s .com domain. Google cut off their cloud infrastructure and used Play Protect to disable infected apps on users’ devices.
Here’s how it worked. NetNut operatives infected devices through trojanized apps or pre-installed malware — think Badbox 2.0. Once compromised, those devices became proxy exit nodes. Attackers routed their traffic through real home IP addresses, making it look legitimate. Hard to block. Harder to trace.
That’s the appeal of residential proxies. They let criminals hide behind your smart TV’s internet connection.
GTIG spotted 316 distinct threat clusters using NetNut in a single week last month. Cybercriminal groups. Espionage actors. Everyone was leaning on this network.
The takedown won’t stop the problem entirely. Mark Karayan from Mandiant put it bluntly: when one proxy service goes down, operators just buy replacement capacity from competitors. The industry is deeply interconnected, and NetNut was one of the biggest suppliers.
Still, this is a significant disruption. Google’s shared technical details on NetNut’s SDKs and C2 infrastructure with law enforcement and security researchers worldwide. That intelligence will make it harder for replacement services to spin up unnoticed.
This follows Google’s earlier takedown of IPIDEA, another residential proxy network fueled by malware. The pattern is clear — these networks keep getting built, and Google keeps taking them apart.
