<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt" -->

---
title: Google and FBI Dismantle NetNut Residential Proxy Botnet
description: Google&#x27;s Threat Intelligence Group, the FBI, and IRS Criminal Investigation have dismantled NetNut, a residential proxy botnet spanning over two million...
canonical: https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Google and FBI Dismantle NetNut Residential Proxy Botnet | daily.dev
og:description: Google&#x27;s Threat Intelligence Group, the FBI, and IRS Criminal Investigation have dismantled NetNut, a residential proxy botnet spanning over two million...
og:url: https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt
og:image: https://api.daily.dev/og/posts/iUsQk4knt.png
og:image:alt: Google and FBI Dismantle NetNut Residential Proxy Botnet
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Google and FBI Dismantle NetNut Residential Proxy Botnet

**[Latest Hacking News](https://daily.dev/sources/lhn)** · 4 min read · 8 upvotes · 1 comments

## Summary

Google's Threat Intelligence Group, the FBI, and IRS Criminal Investigation have dismantled NetNut, a residential proxy botnet spanning over two million hijacked smart TVs, streaming boxes, and Android devices. Commercially sold under the NetNut brand by Alarum Technologies (a Nasdaq-listed Israeli company), the network was used by 316 distinct threat clusters for password spraying, ad fraud, content scraping, and account takeover. Google disabled NetNut's Google account infrastructure and pushed detection into Play Protect, while the FBI seized hundreds of associated domains. Research found over 20% of Samsung Tizen apps and 42% of LG webOS apps contained a residential proxy SDK without user disclosure. The same infected hardware also hosted Mirai DDoS variants and was linked to the Badbox 2.0 Android botnet. Google describes this as 'significant degradation' rather than a full kill, noting that proxy providers share capacity with rivals, making complete takedowns difficult.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://latesthackingnews.com/2026/07/03/residential-proxy-botnet-netnut-takedown>

## Questions this post answers

### What was the NetNut residential proxy botnet and how did devices get infected?

NetNut, tracked by researchers as Popa, was a residential proxy network built from over two million hijacked smart TVs, streaming boxes and Android devices. Devices were compromised either through pre-installed proxy code shipped on budget hardware or through free apps bundling a hidden SDK; Spur found the SDK in over 20% of Samsung Tizen apps and 42% of LG webOS apps tested.

_daily.dev surfaces security research like this for teams hardening app supply chains against hidden SDKs._

### How did Google and the FBI take down the NetNut proxy botnet?

Google's Threat Intelligence Group disabled the Google accounts and services NetNut used for command and control on July 2, while the FBI, working with the IRS Criminal Investigation division, seized hundreds of domains tied to the network. Google also added Play Protect detection so Android devices are warned about apps carrying NetNut's proxy code, with known offenders disabled automatically.

_Following coordinated takedowns like this helps security teams anticipate how proxy infrastructure gets disrupted._

### What was NetNut's residential proxy botnet used for by cybercriminals?

Google tracked 316 distinct threat clusters using suspected NetNut exit nodes in a single week in June, spanning cybercriminal and espionage-linked groups. The most common use was password spraying, spreading login attempts across thousands of residential IPs to evade volume-based monitoring; Krebs on Security also reported it was rented for content scraping, ad fraud and account takeover.

_Teams tuning authentication monitoring against distributed low-and-slow attacks can track this kind of threat intelligence on daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@starfallcodes** · 1 upvotes

> yay my tv is no longer ddos-ing

## Similar posts on daily.dev

- [Google’s Continued Disruption of Malicious Residential Proxy Networks](https://daily.dev/posts/google-s-continued-disruption-of-malicious-residential-proxy-networks-6zdypafgl) · Google Cloud · 1 upvotes · 0 comments
- [FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security](https://daily.dev/posts/fbi-seizes-netnut-proxy-platform-popa-botnet-krebs-on-security-kdkdrksub) · Krebs on Security · 3 upvotes · 0 comments
- [NetNut proxy network disrupted, 2 million infected devices cut off](https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8) · BleepingComputer · 1 upvotes · 0 comments
- [‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security](https://daily.dev/posts/popa-botnet-linked-to-publicly-traded-israeli-firm-krebs-on-security-uiuu7khvo) · Krebs on Security · 1 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Google and FBI Dismantle NetNut Residential Proxy Botnet","url":"https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt"},"datePublished":"2026-07-03T12:15:04.868Z","dateModified":"2026-09-14T08:50:53.791Z","description":"Google's Threat Intelligence Group, the FBI, and IRS Criminal Investigation have dismantled NetNut, a residential proxy botnet spanning over two million...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/493d922b5bf3ba19126490ec411038d0?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/493d922b5bf3ba19126490ec411038d0?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Latest Hacking News","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Latest Hacking News","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/5110318ded6e43f1bb12facdeb2b1965","url":"https://daily.dev/sources/lhn"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":8},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"malware","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Latest Hacking News","item":"https://daily.dev/sources/lhn"},{"@type":"ListItem","position":3,"name":"Google and FBI Dismantle NetNut Residential Proxy Botnet"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt","comment":[{"@type":"Comment","text":"yay my tv is no longer ddos-ing","datePublished":"2026-07-03T12:51:57.112Z","url":"https://daily.dev/posts/iUsQk4knt#c-Ri3F1jZ37","author":{"@type":"Person","name":"Starfall :D","url":"https://daily.dev/starfallcodes","image":"https://media.daily.dev/image/upload/s--4xoTqFbk--/f_auto/v1786806197/avatars/avatar_ecPDW57nUVRidLxwsxruz?_a=BAMAMicg0"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt#faq","mainEntity":[{"@type":"Question","name":"What was the NetNut residential proxy botnet and how did devices get infected?","acceptedAnswer":{"@type":"Answer","text":"NetNut, tracked by researchers as Popa, was a residential proxy network built from over two million hijacked smart TVs, streaming boxes and Android devices. Devices were compromised either through pre-installed proxy code shipped on budget hardware or through free apps bundling a hidden SDK; Spur found the SDK in over 20% of Samsung Tizen apps and 42% of LG webOS apps tested. daily.dev surfaces security research like this for teams hardening app supply chains against hidden SDKs."}},{"@type":"Question","name":"How did Google and the FBI take down the NetNut proxy botnet?","acceptedAnswer":{"@type":"Answer","text":"Google's Threat Intelligence Group disabled the Google accounts and services NetNut used for command and control on July 2, while the FBI, working with the IRS Criminal Investigation division, seized hundreds of domains tied to the network. Google also added Play Protect detection so Android devices are warned about apps carrying NetNut's proxy code, with known offenders disabled automatically. Following coordinated takedowns like this helps security teams anticipate how proxy infrastructure gets disrupted."}},{"@type":"Question","name":"What was NetNut's residential proxy botnet used for by cybercriminals?","acceptedAnswer":{"@type":"Answer","text":"Google tracked 316 distinct threat clusters using suspected NetNut exit nodes in a single week in June, spanning cybercriminal and espionage-linked groups. The most common use was password spraying, spreading login attempts across thousands of residential IPs to evade volume-based monitoring; Krebs on Security also reported it was rented for content scraping, ad fraud and account takeover. Teams tuning authentication monitoring against distributed low-and-slow attacks can track this kind of threat intelligence on daily.dev."}}]}
```

