Google, in collaboration with the FBI, Lumen, and others, conducted a significant disruption of the NetNut residential proxy network. The network consisted of over 2 million compromised devices, mainly Android appliances like smart TVs and streaming boxes, which were being misused to help cybercriminals hide malicious traffic behind legitimate residential IPs.
The operation included disabling Google accounts and services used by NetNut for command-and-control purposes, a critical step in undermining the botnet's backend infrastructure. Google Play Protect was updated to disable applications known to incorporate NetNut software development kits (SDKs), further securing users' devices.
By degrading the operational capacity of the NetNut proxy network, the coordinated action has reduced the number of devices available for use by cybercriminals and espionage groups. Such groups previously rented these residential proxies to obfuscate their operations, thereby evading detection.
NetNut, also known as Popa, is linked to the Israeli company Alarum Technologies. This disruption follows a January 2026 action against IPIDEA, showing continued efforts to dismantle malicious proxy networks. The disabling of command-and-control infrastructure mitigates risk by preventing hackers from using residential IPs to launch coordinated attacks.
The joint efforts demonstrate a proactive approach in safeguarding user devices from being unknowingly exploited by cybercriminals. Enhanced awareness and updated protections emphasize the need for continued vigilance in cybersecurity at the level of both personal devices and larger infrastructures.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Google and the FBI disrupted the NetNut proxy network, estimated to involve 2 million devices. This action is crucial as it targets malware command-and-control operations, mitigating risks from home devices being used in cybercriminal activities.
A joint operation including Google has dismantled the NetNut residential proxy network, which controlled at least two million compromised devices. This disruption is significant as it obstructs the activities of cybercriminals and espionage groups using these devices to hide their traffic behind legitimate residential IP addresses.
Google and the FBI dismantled the NetNut residential proxy network, which operated over 2 million compromised Android devices. This operation is significant as it targets a major infrastructure for cybercriminals, disrupting their access and capabilities for malicious activities.
Google, in partnership with the FBI, has degraded the NetNut proxy network, which utilized over 2 million home devices as exit nodes for malicious traffic. This disruption is significant as it reduces the ability of attackers to obfuscate their actions and access other devices within affected networks.
Google, in collaboration with the FBI and Lumen, has disrupted the NetNut residential proxy network, aiming to dismantle malicious proxy services. This action follows a similar disruption of the IPIDEA network and aims to decrease the operational capacity of NetNut and its resellers.