# Google and FBI Dismantle NetNut: 2+ Million-Device Residential Proxy Botnet Dismantled in Coordinated International Operation
In a landmark coordinated takedown, Google, the FBI, and international law enforcement agencies have successfully disrupted NetNut (also known as Popa), one of the largest residential proxy botnets ever documented. The operation dealt a significant blow to a criminal infrastructure that had infected over 2 million Android devices and was actively rented to hundreds of threat actors—including nation-state espionage groups—seeking to mask their identities during cyberattacks.
## The Threat: A Massive Infrastructure for Hiding Attackers
NetNut operated as a for-profit botnet-as-a-service platform, functioning similarly to a malicious VPN provider. The network consisted of compromised Android devices—primarily smart TVs and streaming boxes—that had been infected with malware, including the notorious Badbox 2.0 trojan. These compromised devices unknowingly relayed traffic for cybercriminals, allowing attackers to obscure their true geographic locations and IP addresses during cyberattacks.
According to Google's Threat Analysis Group, the scale of abuse was staggering. In a single week in June 2026, Google observed 316 distinct threat clusters leveraging NetNut's proxy infrastructure to conduct password-spray attacks and establish persistent access to victim networks. These threat actors represented both traditional cybercriminal organizations and state-sponsored groups, creating a dangerous fusion of criminal and geopolitical threats operating from a single platform.
## How NetNut Infected Millions of Devices
The infection vector relied on social engineering and malware distribution. Threat operators behind NetNut:
Once infected, devices became part of the rental pool, generating revenue for the network operator each time a threat actor routed traffic through them.
## The Operator: Links to Alarum Technologies Ltd
Google's investigation traced NetNut's operations to individuals affiliated with Alarum Technologies Ltd, an Israeli publicly-traded company. The connection between Alarum and the illegal proxy network operation highlights a concerning trend: the convergence of legitimate business entities and criminal infrastructure.
The organization's legitimacy on the public markets—combined with its control of a massive criminal botnet—raises questions about corporate governance, due diligence, and the oversight mechanisms designed to prevent publicly-traded companies from harboring cybercriminal operations.
## The Takedown: Infrastructure Destruction and Device Recovery
The coordinated takedown operation targeted NetNut's operational infrastructure from multiple angles:
| Action | Impact |
|--------|--------|
| Google Account Disablement | Eliminated command-and-control (C&C) systems and backend infrastructure |
| Google Play Protect Removal | Automatically uninstalled infected applications from victim devices |
| User Notifications | Warned millions of device owners of their compromise |
| Threat Intelligence Sharing | Distributed IOCs and detection patterns to industry and law enforcement |
| Device Recovery | Reduced available proxy capacity by millions of devices |
"We believe our coordinated actions have caused significant degradation to NetNut's proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions," Google stated, though the company acknowledged that complete eradication remains an ongoing challenge.
## Implications for Organizations and Defenders
Password-Spray Attacks: NetNut's primary use case—enabling large-scale password-spray attacks—poses a direct threat to any organization with cloud services or internet-facing authentication systems. Attackers using the proxy network could attempt millions of login combinations while remaining invisible to traditional IP-based detection systems.
Lateral Movement and Data Exfiltration: Once inside networks, attackers used the residential proxy infrastructure to move laterally between systems and exfiltrate data while masking the true origin of the traffic, evading geographic-based security controls.
Nation-State Espionage: The presence of state-sponsored threat actors on the platform suggests that hostile governments have been using NetNut to conduct intelligence gathering and infrastructure probing operations with plausible deniability.
## The Reseller Ecosystem: Why Complete Disruption Remains Difficult
Google's analysis revealed a troubling business model: NetNut operated a reseller program allowing other companies to white-label the botnet infrastructure under their own brand names. This fragmented the network across multiple retail identities, complicating takedown efforts and creating redundancy.
The disruption has already triggered a predictable ecosystem response: "When faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller," Google observed. This adaptation suggests that defeating residential proxy threats requires targeting not just individual botnets, but the interconnected infrastructure supporting the entire proxy ecosystem.
## Defensive Recommendations
Organizations should implement the following measures:
## HackWire Analysis
The NetNut takedown represents a watershed moment in botnet disruption strategy, but also reveals the limits of traditional law enforcement action against infrastructure-as-a-crime business models.
The operation's significance lies not just in the scale—2+ million devices dwarfs most prior botnets—but in the *sophistication of its business model*. NetNut wasn't a crude DDoS botnet generating random traffic; it was a precision infrastructure provider carefully engineered for professional threat actors. By renting access to compromised devices, the operator created a service that adversaries preferred to their own botnets because it enabled them to obscure their origin while maintaining reliability.
The reseller component is the operation's true innovation—and its Achilles' heel for lasting disruption. When Google degraded NetNut, operators didn't retire; they became customers for competitor botnets like IPIDEA (disrupted in January). This reveals a fundamental problem: treating botnets as isolated targets, rather than nodes in an interconnected supply chain, allows the threat to metastasize.
Google's acknowledgment that "creating lasting disruption requires scaling efforts to target infrastructure of several interconnected providers" signals a strategic shift toward ecosystem-wide takedowns. This is correct, but it also implies that single-botnet operations will have diminishing returns.
For defenders, the immediate implication is clear: password-spray attacks enabled by residential proxies are now the default attack method for any threat actor seeking stealth. MFA and conditional access are no longer options—they're minimum survival requirements. The concerning development is that residential proxy infrastructure is becoming *commoditized*, with dozens of competing networks offering similar services. Disrupting one creates temporary pressure; disrupting the ecosystem requires coordination at a scale most previous operations haven't achieved.
— HackWire Editorial
## Related Coverage