Google, working with the FBI and Lumen, has taken a sledgehammer to NetNut. The residential proxy network — also known as Popa — had at least 2 million devices enrolled worldwide. That pool just got cut by millions.
Here’s what NetNut does. It turns home gadgets — smart TVs, streaming boxes, Android devices — into exit nodes. Strangers route their traffic through your internet connection. Your IP address gets the heat for whatever they do.
Google’s Threat Intelligence Group counted 316 distinct threat clusters using NetNut in a single week. Cybercriminals. Espionage groups. Password-spray attacks. All hiding behind real home IPs.
NetNut is unusual because it traces back to a public company: Alarum Technologies (NASDAQ: ALAR). Researchers at Qurium, Synthient, Nokia Deepfield, and Spur tied Popa directly to NetNut’s commercial proxy service. Synthient proved the traffic path by sending data into NetNut’s gateway and watching it emerge from a Popa-infected device.
Alarum denies the botnet label. Says its software is consensual bandwidth-sharing. But Synthient tested over 20 apps and found none of them showed users a consent prompt.
The takedown follows Google’s earlier disruption of IPIDEA, a China-based rival. Each time these networks get hit, operators buy capacity from competitors and rebrand. Google says lasting damage means going after multiple providers simultaneously.
Bottom line for consumers: don’t buy cheap no-name streaming boxes. Stick to official app stores. And if an app offers to pay you for “sharing your bandwidth,” it’s probably this.
