Google's Threat Intelligence Group, the FBI, and IRS Criminal Investigation have dismantled NetNut, a residential proxy botnet spanning over two million hijacked smart TVs, streaming boxes, and Android devices. Commercially sold under the NetNut brand by Alarum Technologies (a Nasdaq-listed Israeli company), the network was used by 316 distinct threat clusters for password spraying, ad fraud, content scraping, and account takeover. Google disabled NetNut's Google account infrastructure and pushed detection into Play Protect, while the FBI seized hundreds of associated domains. Research found over 20% of Samsung Tizen apps and 42% of LG webOS apps contained a residential proxy SDK without user disclosure. The same infected hardware also hosted Mirai DDoS variants and was linked to the Badbox 2.0 Android botnet. Google describes this as 'significant degradation' rather than a full kill, noting that proxy providers share capacity with rivals, making complete takedowns difficult.
Table of contents
What Google and the FBI actually didHow two million devices became a residential proxy botnetWho was buying accessWhy this takedown won’t be the last word14.7K Impressions1 Comment