<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8" -->

---
title: NetNut proxy network disrupted, 2 million infected...
description: A joint law enforcement and industry operation led by Google, the FBI, Lumen Technologies, and The Shadowserver Foundation has disrupted NetNut (also known as...
canonical: https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: NetNut proxy network disrupted, 2 million infected devices cut off | daily.dev
og:description: A joint law enforcement and industry operation led by Google, the FBI, Lumen Technologies, and The Shadowserver Foundation has disrupted NetNut (also known as...
og:url: https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8
og:image: https://api.daily.dev/og/posts/yWIBtnJA8.png
og:image:alt: NetNut proxy network disrupted, 2 million infected devices cut off
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# NetNut proxy network disrupted, 2 million infected devices cut off

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

A joint law enforcement and industry operation led by Google, the FBI, Lumen Technologies, and The Shadowserver Foundation has disrupted NetNut (also known as Popa), one of the world's largest residential proxy botnets. The network comprised at least 2 million compromised Android devices — including smart TVs and streaming boxes — infected via trojanized apps and pre-installed malware. Threat actors used NetNut to hide malicious traffic behind legitimate residential IP addresses, with 316 distinct threat clusters observed using its exit nodes in a single week. Google disabled NetNut's C2 infrastructure, warned users via Google Play Protect, and shared SDK and backend details with partners. The FBI seized the netnut.com domain. Because NetNut operates a reseller program powering many other proxy services, the disruption is expected to have broad ripple effects across the residential proxy industry.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off>

## Questions this post answers

### What is the NetNut proxy botnet and how many devices did it infect?

NetNut, also known as Popa, is a residential proxy network estimated to control at least two million infected devices globally, including Android smart TVs and streaming boxes. Devices are compromised through trojanized applications and botnets like Badbox 2.0 that package proxy plugins, letting operators sell access to attackers who route traffic through victims' residential IP addresses.

_Security teams tracking proxy botnet takedowns can follow disruption details like this on daily.dev._

### Who took down the NetNut residential proxy network and how was it disrupted?

A joint operation involving Google, the FBI, Lumen Technologies, and The Shadowserver Foundation dismantled NetNut. The FBI seized the netnut.com domain, Google disabled the accounts and services NetNut used for command-and-control on its infrastructure, disabled infected apps via Google Play Protect, and shared SDK and C2 technical details with law enforcement and industry partners.

_Anyone tracking coordinated botnet takedowns can keep up with cases like this via daily.dev._

### How many threat actors were using the NetNut proxy network before it was disrupted?

Google Threat Intelligence Group observed 316 distinct threat clusters using suspected NetNut exit nodes in a single week, including cybercriminal and espionage groups. Threat actors used NetNut to access their own infrastructure, conduct password-spraying attacks, and reach victim environments while hiding behind legitimate residential IP addresses.

_Those assessing residential proxy risk in threat models can find incident writeups like this on daily.dev._

## Similar posts on daily.dev

- [Google’s Continued Disruption of Malicious Residential Proxy Networks](https://daily.dev/posts/google-s-continued-disruption-of-malicious-residential-proxy-networks-6zdypafgl) · Google Cloud · 1 upvotes · 0 comments
- [FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security](https://daily.dev/posts/fbi-seizes-netnut-proxy-platform-popa-botnet-krebs-on-security-kdkdrksub) · Krebs on Security · 3 upvotes · 0 comments
- [Google and FBI Dismantle NetNut Residential Proxy Botnet](https://daily.dev/posts/google-and-fbi-dismantle-netnut-residential-proxy-botnet-iusqk4knt) · Latest Hacking News · 8 upvotes · 1 comments
- [‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm – Krebs on Security](https://daily.dev/posts/popa-botnet-linked-to-publicly-traded-israeli-firm-krebs-on-security-uiuu7khvo) · Krebs on Security · 1 upvotes · 0 comments

---

Tags: [#google](https://daily.dev/tags/google), [#android](https://daily.dev/tags/android), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"NetNut proxy network disrupted, 2 million infected devices cut off","url":"https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8"},"datePublished":"2026-07-05T02:44:17.300Z","dateModified":"2026-09-13T21:52:06.678Z","description":"A joint law enforcement and industry operation led by Google, the FBI, Lumen Technologies, and The Shadowserver Foundation has disrupted NetNut (also known as...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/da3164c0a2dd6fc46132620146546279?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/da3164c0a2dd6fc46132620146546279?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"google,android,malware","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"NetNut proxy network disrupted, 2 million infected devices cut off"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off-ywibtnja8#faq","mainEntity":[{"@type":"Question","name":"What is the NetNut proxy botnet and how many devices did it infect?","acceptedAnswer":{"@type":"Answer","text":"NetNut, also known as Popa, is a residential proxy network estimated to control at least two million infected devices globally, including Android smart TVs and streaming boxes. Devices are compromised through trojanized applications and botnets like Badbox 2.0 that package proxy plugins, letting operators sell access to attackers who route traffic through victims' residential IP addresses. Security teams tracking proxy botnet takedowns can follow disruption details like this on daily.dev."}},{"@type":"Question","name":"Who took down the NetNut residential proxy network and how was it disrupted?","acceptedAnswer":{"@type":"Answer","text":"A joint operation involving Google, the FBI, Lumen Technologies, and The Shadowserver Foundation dismantled NetNut. The FBI seized the netnut.com domain, Google disabled the accounts and services NetNut used for command-and-control on its infrastructure, disabled infected apps via Google Play Protect, and shared SDK and C2 technical details with law enforcement and industry partners. Anyone tracking coordinated botnet takedowns can keep up with cases like this via daily.dev."}},{"@type":"Question","name":"How many threat actors were using the NetNut proxy network before it was disrupted?","acceptedAnswer":{"@type":"Answer","text":"Google Threat Intelligence Group observed 316 distinct threat clusters using suspected NetNut exit nodes in a single week, including cybercriminal and espionage groups. Threat actors used NetNut to access their own infrastructure, conduct password-spraying attacks, and reach victim environments while hiding behind legitimate residential IP addresses. Those assessing residential proxy risk in threat models can find incident writeups like this on daily.dev."}}]}
```

