Google, in coordination with the FBI and Lumen, disrupted the NetNut residential proxy network (also known as Popa), estimated to control at least 2 million hijacked consumer devices worldwide. Actions included disabling Google accounts used for malware C2, sharing technical intelligence with law enforcement and platform providers, and using Google Play Protect to warn users and disable apps containing NetNut SDKs. NetNut populates its botnet via SDKs embedded in smart TVs and streaming boxes, and operates a whitelabel reseller program used by many popular proxy brands. In a single week in June 2026, 316 distinct threat clusters — including cybercriminal and espionage groups — were observed using NetNut exit nodes for password spraying, origin masking, and lateral movement into home networks. Google warns consumers against apps offering payment for unused bandwidth and urges use of official app stores and Play Protect-certified devices.