Friday, September 11, 2026

Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks

Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks.

This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026.

This action is part of an ongoing campaign to dismantle malicious residential proxy ecosystems, following the earlier takedown of the IPIDEA network in January 2026.

Google Disrupts NetNut Residential Proxy Botnet

As part of the operation, Google disabled accounts and services used by NetNut operators to manage malware C2 infrastructure, citing violations of its Acceptable Use Policy.

The company also shared detailed technical intelligence, including indicators related to NetNut SDKs and backend infrastructure, with law enforcement and security vendors to enhance broader detection and mitigation efforts.

Additionally, Google Play Protect was updated to automatically identify and block Android applications embedding NetNut-related components, preventing further infections and protecting users from compromised apps.

GTIG assesses that this disruption significantly degraded NetNut’s operational capacity, reducing its pool of compromised residential devices by millions.

The botnet, also known as “Popa,” is estimated to have infected at least 2 million devices globally. NetNut’s business model includes a reseller and whitelabeling ecosystem, allowing multiple proxy services to operate on its infrastructure.

Malicious Devices (Source: Krebs On Security)
Malicious Devices (Source: Krebs On Security)

Google noted that several popular residential proxy providers are likely reselling access to NetNut’s botnet, amplifying its reach among cybercriminals and in gray-market services.

Residential proxy networks like NetNut enable threat actors to route malicious traffic through legitimate ISP-assigned IP addresses, effectively masking their origin and evading traditional detection techniques.

These networks rely on compromised consumer devices acting as exit nodes, often infected via preloaded malware on IoT devices or applications containing hidden proxy SDKs.

GTIG identified NetNut components embedded in various malware ecosystems, including integrations with botnets like Badbox 2.0 and variants associated with Mirai-based distributed denial-of-service (DDoS) campaigns.

In June 2026 alone, Google tracked 316 distinct threat clusters utilizing suspected NetNut exit nodes. These included financially motivated cybercriminal groups and state-aligned espionage actors using the infrastructure for anonymized access, lateral movement, and large-scale password spraying.

The presence of proxy malware on consumer devices introduces additional risks, as unauthorized traffic routed through home networks can expose internal systems to external threats, potentially leading to reputational damage or service disruptions for affected users.

Security researchers have consistently highlighted the growing abuse of residential proxies in cyber operations. Reports from multiple firms indicate that compromised devices not only facilitate but also enable anonymized attacks.

However, they can also enable lateral movement within home networks. This increases the attack surface for adversaries, complicating attribution efforts for defenders.

Google emphasized that consumer awareness is critical in combating such threats. Users are advised to avoid applications offering compensation for “sharing bandwidth,” verify app permissions, and ensure device integrity by using certified platforms and built-in protections like Play Protect.

The company also urged caution when purchasing connected devices, recommending verification of vendor authenticity and certification status.

Despite the impact of this disruption, GTIG warns that the residential proxy ecosystem remains highly adaptive and interconnected. Operators often compensate for takedowns by leasing capacity from competing botnets, maintaining continuity through decentralized infrastructure.

Google stated that it will continue mapping relationships between proxy providers and collaborating with industry stakeholders to target shared infrastructure and achieve long-term disruption of malicious proxy networks.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News