← All stories
● Covered by 4 sources · 5 reportsMedium impact

Google and FBI Disrupt NetNut Proxy Network of 2 Million Devices

🔄 Updated 41d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • NetNut network involved over 2 million compromised devices.
  • Google partnered with FBI and Lumen for the disruption.
  • Command-and-control infrastructure was disabled.
  • Residential IPs were used to hide malicious activities.
  • NetNut is linked to Israeli firm Alarum Technologies.

Overview of the Disruption

Google, in collaboration with the FBI, Lumen, and others, conducted a significant disruption of the NetNut residential proxy network. The network consisted of over 2 million compromised devices, mainly Android appliances like smart TVs and streaming boxes, which were being misused to help cybercriminals hide malicious traffic behind legitimate residential IPs.

Details of the Operation

The operation included disabling Google accounts and services used by NetNut for command-and-control purposes, a critical step in undermining the botnet's backend infrastructure. Google Play Protect was updated to disable applications known to incorporate NetNut software development kits (SDKs), further securing users' devices.

Impact on Cybercrime Activities

By degrading the operational capacity of the NetNut proxy network, the coordinated action has reduced the number of devices available for use by cybercriminals and espionage groups. Such groups previously rented these residential proxies to obfuscate their operations, thereby evading detection.

Significance of the Takendown

NetNut, also known as Popa, is linked to the Israeli company Alarum Technologies. This disruption follows a January 2026 action against IPIDEA, showing continued efforts to dismantle malicious proxy networks. The disabling of command-and-control infrastructure mitigates risk by preventing hackers from using residential IPs to launch coordinated attacks.

Conclusion

The joint efforts demonstrate a proactive approach in safeguarding user devices from being unknowingly exploited by cybercriminals. Enhanced awareness and updated protections emphasize the need for continued vigilance in cybersecurity at the level of both personal devices and larger infrastructures.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Google and the FBI disrupted the NetNut proxy network, estimated to involve 2 million devices. This action is crucial as it targets malware command-and-control operations, mitigating risks from home devices being used in cybercriminal activities.

A joint operation including Google has dismantled the NetNut residential proxy network, which controlled at least two million compromised devices. This disruption is significant as it obstructs the activities of cybercriminals and espionage groups using these devices to hide their traffic behind legitimate residential IP addresses.

Google and the FBI dismantled the NetNut residential proxy network, which operated over 2 million compromised Android devices. This operation is significant as it targets a major infrastructure for cybercriminals, disrupting their access and capabilities for malicious activities.

Google, in partnership with the FBI, has degraded the NetNut proxy network, which utilized over 2 million home devices as exit nodes for malicious traffic. This disruption is significant as it reduces the ability of attackers to obfuscate their actions and access other devices within affected networks.

Google, in collaboration with the FBI and Lumen, has disrupted the NetNut residential proxy network, aiming to dismantle malicious proxy services. This action follows a similar disruption of the IPIDEA network and aims to decrease the operational capacity of NetNut and its resellers.