Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks.
This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026.
This action is part of an ongoing campaign to dismantle malicious residential proxy ecosystems, following the earlier takedown of the IPIDEA network in January 2026.
Google Disrupts NetNut Residential Proxy Botnet
As part of the operation, Google disabled accounts and services used by NetNut operators to manage malware C2 infrastructure, citing violations of its Acceptable Use Policy.
The company also shared detailed technical intelligence, including indicators related to NetNut SDKs and backend infrastructure, with law enforcement and security vendors to enhance broader detection and mitigation efforts.
Additionally, Google Play Protect was updated to automatically identify and block Android applications embedding NetNut-related components, preventing further infections and protecting users from compromised apps.
GTIG assesses that this disruption significantly degraded NetNut’s operational capacity, reducing its pool of compromised residential devices by millions.
The botnet, also known as “Popa,” is estimated to have infected at least 2 million devices globally. NetNut’s business model includes a reseller and whitelabeling ecosystem, allowing multiple proxy services to operate on its infrastructure.

Google noted that several popular residential proxy providers are likely reselling access to NetNut’s botnet, amplifying its reach among cybercriminals and in gray-market services.
Residential proxy networks like NetNut enable threat actors to route malicious traffic through legitimate ISP-assigned IP addresses, effectively masking their origin and evading traditional detection techniques.
These networks rely on compromised consumer devices acting as exit nodes, often infected via preloaded malware on IoT devices or applications containing hidden proxy SDKs.
GTIG identified NetNut components embedded in various malware ecosystems, including integrations with botnets like Badbox 2.0 and variants associated with Mirai-based distributed denial-of-service (DDoS) campaigns.
In June 2026 alone, Google tracked 316 distinct threat clusters utilizing suspected NetNut exit nodes. These included financially motivated cybercriminal groups and state-aligned espionage actors using the infrastructure for anonymized access, lateral movement, and large-scale password spraying.
The presence of proxy malware on consumer devices introduces additional risks, as unauthorized traffic routed through home networks can expose internal systems to external threats, potentially leading to reputational damage or service disruptions for affected users.
Security researchers have consistently highlighted the growing abuse of residential proxies in cyber operations. Reports from multiple firms indicate that compromised devices not only facilitate but also enable anonymized attacks.
However, they can also enable lateral movement within home networks. This increases the attack surface for adversaries, complicating attribution efforts for defenders.
Google emphasized that consumer awareness is critical in combating such threats. Users are advised to avoid applications offering compensation for “sharing bandwidth,” verify app permissions, and ensure device integrity by using certified platforms and built-in protections like Play Protect.
The company also urged caution when purchasing connected devices, recommending verification of vendor authenticity and certification status.
Despite the impact of this disruption, GTIG warns that the residential proxy ecosystem remains highly adaptive and interconnected. Operators often compensate for takedowns by leasing capacity from competing botnets, maintaining continuity through decentralized infrastructure.
Google stated that it will continue mapping relationships between proxy providers and collaborating with industry stakeholders to target shared infrastructure and achieve long-term disruption of malicious proxy networks.
Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN





