# Google and FBI Disrupt NetNut Residential Proxy Botnet, Isolating 2 Million Infected Devices


A coordinated international operation led by Google and the Federal Bureau of Investigation has successfully disrupted NetNut, one of the world's largest residential proxy botnets. The takedown severed access to approximately 2 million compromised devices—including Android phones, smart TVs, and streaming boxes—that cybercriminals and espionage groups had weaponized to mask their malicious activities behind legitimate home internet addresses.


The operation represents a significant blow to the underground proxy-as-a-service industry, which has become a critical infrastructure for threat actors conducting everything from credential-stuffing attacks to sophisticated reconnaissance operations. However, security researchers warn that the victory may be temporary, as the highly interconnected proxy reseller market rapidly redistributes botnet capacity among competing criminal services.


## The Threat: Residential Proxies as a Criminal Weapon


Residential proxy networks operate by converting compromised home devices into illicit exit nodes—essentially turning innocent users' internet connections into relay points for criminal traffic. Unlike datacenter proxies, which are easily identified and blocked by security systems, residential proxies use legitimate home IP addresses that blend seamlessly with normal user activity.


NetNut's operational model included:


  • Massive device recruitment: 2+ million compromised Android devices, smart TVs, streaming boxes, and IoT devices globally
  • Trojanized distribution: Malware pre-installed on devices at the factory level or delivered through malicious applications
  • Botnet variants: Use of sophisticated malware families like Badbox 2.0 that packaged proxy functionality within seemingly legitimate apps
  • Reseller infrastructure: A complex ecosystem allowing hundreds of third parties to re-brand and resell NetNut capacity
  • Enterprise-scale operations: Support for hundreds of distinct threat actors, from cybercriminals to nation-state espionage groups

  • The service operated across multiple domains, with netnut.com serving as its primary public-facing interface before being seized by the FBI.


    ## How the Network Functioned


    NetNut worked by compromising devices and installing software that silently routed malicious traffic through the victim's home internet connection. Threat actors paid subscription fees to use these residential exit nodes for various attacks.


    | Attack Vector | Description |

    |---|---|

    | Password Spraying | Distributed credential attacks appearing to originate from thousands of home addresses |

    | Account Takeover | Access to victim infrastructure while masking their true location and origin |

    | Web Scraping | Circumventing rate limiting and geographic restrictions |

    | Reconnaissance | Scanning victim networks while appearing as residential traffic |

    | Evasion | Bypassing security controls that block datacenter IP ranges |


    According to Google's Threat Intelligence Group (GTIG), the scale of abuse was staggering: in a single week last month, GTIG observed 316 distinct threat clusters actively using suspected NetNut exit nodes, including both criminal and espionage-focused threat actors.


    ## The Disruption: A Multi-Agency Takedown


    The operation brought together an unprecedented coalition of government agencies, technology companies, and infrastructure providers:


  • Google: Disabled C2 infrastructure, removed infected applications, and coordinated the technical takedown
  • Federal Bureau of Investigation: Seized domains and coordinated law enforcement response
  • Lumen Technologies: Provided critical infrastructure support
  • The Shadowserver Foundation: Assisted with technical analysis and coordination
  • Additional partners: International law enforcement and cybersecurity firms

  • Google's response was comprehensive. The company:


    1. Seized backend infrastructure: Disabled command-and-control (C2) servers that NetNut operators used to manage the botnet

    2. Removed malicious applications: Used Google Play Protect to identify and disable apps containing NetNut proxy code

    3. Automated user protection: Automatically warned affected Android users of infections

    4. Shared intelligence: Distributed technical details about NetNut's SDKs and infrastructure to law enforcement, platform providers, and security researchers

    5. Blocked account access: Terminated the accounts and services NetNut operators maintained on Google's infrastructure


    ## The Scale and Scope of Compromise


    The 2 million devices across NetNut's network represents only the confirmed count—the actual compromised device base may be significantly larger. The geographic distribution and diversity of infected device types illustrate how pervasively residential proxy malware has penetrated consumer IoT ecosystems.


    Device categories compromised:

  • Android smartphones and tablets
  • Smart TVs running Android TV
  • Streaming devices (set-top boxes, media players)
  • Other Android-based IoT devices

  • Geographic reach: Global, with active C2 operations spanning multiple continents


    Operator diversity: Hundreds of threat actors ranging from cybercriminal groups to sophisticated espionage organizations


    ## Implications for Organizations and Users


    Organizations face significant risks from residential proxy networks, which enable threat actors to:


  • Evade detection: Appear as legitimate home users, bypassing perimeter defenses designed to block datacenter IPs
  • Scale attacks: Distribute attacks across thousands of real residential IP addresses simultaneously
  • Target vulnerable systems: Conduct low-and-slow reconnaissance without triggering volumetric-based alerts
  • Access restricted content: Bypass geographic restrictions and rate limiting that protect APIs and services

  • For consumer users, device compromise often occurs silently, with victims unaware their internet connection is being weaponized.


    ## Recommendations for Defense


    For Enterprise Security Teams:


  • Monitor for traffic patterns consistent with residential proxy abuse (distributed login attempts, reconnaissance activity from unexpected residential ranges)
  • Implement adaptive authentication that challenges access from unexpected geographic locations or ISP categories
  • Review logs for signs of credential compromise occurring through distributed attacks
  • Coordinate with ISPs to understand residential IP ranges that may require additional scrutiny
  • Use threat intelligence feeds tracking residential proxy infrastructure

  • For Internet Service Providers:


  • Deploy behavioral analysis to identify devices exhibiting proxy characteristics (unusual traffic patterns, consistent data exfiltration)
  • Implement notifications for customers whose devices show signs of compromise
  • Coordinate with security researchers and law enforcement on botnet takedown efforts

  • For Device Manufacturers:


  • Implement secure boot and verified boot mechanisms to prevent malware pre-installation
  • Conduct supply chain security audits to prevent factory-level infections
  • Deploy built-in security scanning and automatic malware removal capabilities

  • ## HackWire Analysis


    The NetNut disruption is tactically impressive but strategically incomplete—and the industry's structure virtually guarantees a resurgence. Here's what matters: the residential proxy market isn't a niche criminal service; it's become the backbone of modern abuse infrastructure, with hundreds of threat actors depending on it for everything from mundane credential attacks to sophisticated espionage operations. In a single week, 316 distinct threat clusters were actively routing traffic through NetNut alone.


    But here's the critical insight that's being underreported: the proxy industry is essentially a fraud logistics network with built-in redundancy. When NetNut was disrupted, operators didn't go out of business—they simply pivoted to buying capacity from competitors. As Mandiant noted, the industry operates as a densely interconnected reseller network where botnet capacity constantly changes hands. Disrupting one large player redistributes demand to others rather than eliminating the underlying market.


    The real impact of this operation isn't the temporary degradation of available proxy capacity. It's the intelligence harvest. Google shared technical details of NetNut's SDKs and C2 infrastructure with law enforcement and researchers—meaning the 316 threat clusters observed using NetNut can now be more accurately fingerprinted and tracked. That's worth more than the temporary disruption.


    For defenders, the takeaway is unsettling: residential proxy abuse is now a mass-market attack capability. It's no longer confined to sophisticated actors. The barrier to entry is a subscription fee. Organizations need to treat distributed anomalous login attempts and scattered reconnaissance activity from residential IP ranges as a genuine threat class, not an edge case. Expect competitors and threat actors to intensify reliance on proxy networks as law enforcement disruptions temporarily tighten supply.


    This also signals that Google's containment of Android malware—while valuable—has limits. Pre-installed malware and trojanized applications will continue to evade detection in the vast ecosystem of budget Android devices. — HackWire Editorial


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)