Threats · 73 days ago
This is bigger than a botnet clean-up. NetNut was a commercial proxy layer that many unrelated operators rented to make abuse traffic look like ordinary home connections, so disrupting it cuts off access for more than one campaign at once.
Google and the FBI said they disabled the Google accounts and services used for command and control, seized domains, and removed infected apps, which cut millions of residential exit nodes out of service. Google said 316 threat clusters used NetNut nodes in a single week in June for password-spraying, credential-stuffing, fraud, and data scraping, and the service also ran a reseller and whitelabel model that let other brands sell the same infrastructure.
That makes the ripple effect wider than a single network collapse. If buyers of residential proxies shift to competing providers, the same identity-abuse patterns can persist even after NetNut is degraded.
5 sources covering this story
NetNut proxy network disrupted, 2 million infected devices cut off
A joint operation involving Google has disrupted NetNut, a residential proxy network that gave access to millions of compromised Android devices, including smart TVs and streaming boxes.
FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors
The NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnets
Google, FBI Disrupt NetNut Residential Proxy Network Powered by Millions of Devices
NetNut rented access to millions of compromised devices, allowing cybercriminals and nation-state actors to mask their identities during attacks.
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
GTIG says 316 threat clusters used suspected NetNut exit nodes in one June week to hide locations and run password-guessing attacks.
Google’s Continued Disruption of Malicious Residential Proxy Networks | Google Cloud Blog
Google disrupted the NetNut malicious residential proxy network, protecting over 2 million hijacked consumer devices from cybercriminals.
Part of the PlainSec briefing for 2026-07-04