# Google Dismantles NetNut Residential Proxy Network, Disrupting 2 Million Compromised Home Devices


Google's Threat Intelligence Group (GTIG) has dealt a significant blow to NetNut, one of the world's largest residential proxy networks, by effectively disabling millions of compromised home devices that were being rented out to malicious actors. Working alongside the FBI, Lumen Technologies, and other partners, Google's coordinated takedown represents a rare and meaningful disruption to critical infrastructure used to power some of the internet's most persistent cyber threats.


NetNut—also tracked by security researchers under the alias Popa—operated by silently converting ordinary home internet connections into a distributed relay network. Unsuspecting users had their devices compromised and transformed into proxy nodes, allowing attackers to route fraudulent traffic, conduct credential stuffing attacks, scrape protected data, and carry out ad fraud schemes while obscuring their true origin. The scale was staggering: at its peak, the network encompassed approximately 2 million residential devices globally.


## What Is a Residential Proxy Network?


A residential proxy network functions by routing internet traffic through compromised or knowingly cooperating home devices. Unlike data center proxies, which operate from commercial IP addresses easily flagged by security systems, residential proxies use genuine home internet connections that appear legitimate to most web services. This disguise makes them invaluable to cybercriminals.


Common abuse vectors include:

  • Credential stuffing: Testing millions of stolen username-password pairs against target accounts
  • Ad fraud: Generating fake clicks and impressions through legitimate-looking residential IP addresses
  • Web scraping: Harvesting competitor pricing, inventory, or proprietary data without detection
  • Account takeovers: Bypassing geographic authentication controls and security measures
  • Credential abuse: Accessing restricted services as if the user were accessing from home

  • The key advantage for attackers: residential IPs are far more difficult to block than commercial proxies, making detection and mitigation extremely challenging for defenders.


    ## How NetNut Operated


    NetNut deployed its malware through multiple infection vectors. Victims were typically compromised through:


  • Trojanized software: Bundled with legitimate-appearing applications or cracks/keygens
  • Exploit kits: Compromised websites serving drive-by download malware
  • Supply chain attacks: Infected updates from legitimate applications
  • Social engineering: Deceptive download sites and malware-as-a-service offerings

  • Once installed, the malware ran silently in the background, consuming bandwidth and processing power while the device owner remained unaware. NetNut monetized the network by selling access to customers—typically other cybercriminals, but also some less scrupulous commercial entities seeking to evade detection.


    The malware persisted through:

  • Rootkit-like behavior: Resisting removal and antivirus detection
  • Polymorphic updates: Changing signatures regularly to evade detection
  • Anti-analysis techniques: Detecting sandboxes and reversing tools
  • Backup communication channels: Failing over to alternative command-and-control servers if primary channels were blocked

  • ## Google's Disruption Campaign


    Google's intervention operated on multiple fronts simultaneously:


    At the application level:

    Google removed malware installation mechanisms from the Google Play Store and blocked associated apps from installation. This prevented new devices from joining the network.


    At the ISP level:

    Working with Lumen and other major internet service providers, Google coordinated the identification and notification of infected devices. ISPs sent notices to compromised users and, in some cases, temporarily restricted infected devices' ability to function as proxy nodes.


    At the infrastructure level:

    Google disabled known command-and-control servers and sinkholed domain registrations, preventing the botnet from receiving commands or coordinating with infected devices.


    Threat intelligence coordination:

    By publishing detailed threat research identifying NetNut's infrastructure, code signatures, and operational patterns, Google equipped other security vendors and organizations to independently identify and mitigate the threat.


    The cumulative effect: the network lost functional access to approximately millions of previously compromised devices, crippling its operational capacity. According to Google, the network's usable device pool was reduced by a factor of several millions.


    ## Why This Matters Now


    Residential proxy networks represent one of the most overlooked yet critical pieces of modern cybercriminal infrastructure. While attention often focuses on ransomware gangs or zero-day exploits, residential proxy networks enable the everyday operational capability for fraud, data theft, and account compromise at scale.


    The timing is significant for several reasons:


    First, residential proxy abuse has accelerated sharply. The proliferation of APIs, rate-limiting mechanisms, and bot detection has driven attackers to invest more heavily in obfuscation infrastructure. Residential proxies have become less of an optional capability and more of a prerequisite for large-scale attacks.


    Second, the scale of devices involved—2 million—represents an extraordinary concentration of botnet infrastructure in a single criminal enterprise. Most botnets are fragmented across dozens or hundreds of smaller networks. NetNut's size made it strategically important as a shared resource for multiple criminal operations.


    Third, residential proxy networks disproportionately impact vulnerable populations. Compromised devices are concentrated in developing economies where endpoint protection is less prevalent and ISP-level security is minimal. Disrupting the network reduces harm not just to large corporations, but to the global population of infected device owners.


    ## Implications for Organizations


    For defenders:

    Organizations relying on IP reputation and geo-blocking as primary defenses must adapt. The existence of massive residential proxy networks means that:

  • IP-based controls become unreliable for threat detection
  • Behavioral analysis and anomaly detection gain importance
  • Multi-factor authentication becomes nearly essential for account protection
  • Rate limiting and CAPTCHAs offer only marginal protection

  • For the industry:

    This disruption demonstrates that coordinated action—combining law enforcement, private sector threat intelligence, and infrastructure providers—can meaningfully degrade criminal capability. However, it also reveals that individual organizations have limited ability to defend against residential proxy-based attacks without collective action.


    For users:

    The millions of compromised devices highlight how easily mainstream applications can become vectors for malware distribution. Device security depends not only on user behavior but on the security of the software supply chain itself.


    ## What Comes Next


    NetNut's disruption is unlikely to be permanent. The operators will likely rebuild, migrate to new infrastructure, or rebrand. History shows that botnet takedowns typically displace rather than eliminate criminal capability. However, the operation serves several important functions:


  • It raises costs: Rebuilding infrastructure requires investment and time
  • It signals capability: Law enforcement and private sector collaboration can target major criminal operations
  • It opens opportunities: The disruption window allows defenders to update detection signatures and patch vulnerable systems

  • ## Recommendations


    For enterprises:

  • Assume that any account compromise might involve credential stuffing via residential proxies
  • Implement multi-factor authentication on all critical accounts
  • Monitor for impossible travel scenarios and location anomalies
  • Deploy behavioral analytics to detect proxy-based access patterns
  • Increase logging retention for forensic analysis

  • For ISPs and infrastructure providers:

  • Coordinate with security researchers and law enforcement to identify and remediate botnet infrastructure
  • Implement proactive malware detection at the gateway level
  • Notify customers of suspected device compromises with actionable remediation steps

  • For end users:

  • Keep systems fully patched and up to date
  • Use reputable antivirus and anti-malware software
  • Avoid pirated software, cracks, and keygens as infection vectors
  • Monitor device resource usage for signs of compromise

  • ---


    ## HackWire Analysis


    What makes Google's NetNut disruption strategically significant is not just the numbers—though 2 million compromised devices is staggering—but what it reveals about the fragility of large-scale criminal infrastructure when it becomes concentrated. NetNut didn't fail because of a single vulnerability or miscalculation; it failed because its very scale made it a target worth coordinating against. This creates an important inflection point in how defenders and law enforcement think about botnets.


    For years, criminal proxy networks thrived precisely because they were treated as a minor nuisance—uncomfortable for defenders, but not worth the operational effort to disrupt. NetNut's operators apparently believed they were too large and too profitable to take down. But the network's success attracted attention from Google's threat intelligence team and law enforcement, which together could mobilize the resources required for disruption.


    The harder question: what happens next? Residential proxy networks are likely to fragment into smaller, more distributed operations rather than disappearing entirely. This may actually make the problem worse for defenders in some respects—a decentralized network of 50 small botnets is harder to identify and target than one large one. However, the demonstration that coordinated action works is itself valuable. It changes the calculus for operations that become too visible, too profitable, or too damaging.


    The real missed opportunity in this story is the absence of stronger upstream prevention. NetNut was installed primarily through trojanized software and malware-as-a-service offerings. Better software supply chain security, faster incident response from major app stores, and stronger vetting of applications could have prevented millions of devices from being compromised in the first place. Disruption is satisfying, but prevention would have been better. — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)