# Google and FBI Disrupt NetNut Residential Proxy Botnet, Isolating 2 Million Infected Devices
A coordinated international operation led by Google and the Federal Bureau of Investigation has successfully disrupted NetNut, one of the world's largest residential proxy botnets. The takedown severed access to approximately 2 million compromised devices—including Android phones, smart TVs, and streaming boxes—that cybercriminals and espionage groups had weaponized to mask their malicious activities behind legitimate home internet addresses.
The operation represents a significant blow to the underground proxy-as-a-service industry, which has become a critical infrastructure for threat actors conducting everything from credential-stuffing attacks to sophisticated reconnaissance operations. However, security researchers warn that the victory may be temporary, as the highly interconnected proxy reseller market rapidly redistributes botnet capacity among competing criminal services.
## The Threat: Residential Proxies as a Criminal Weapon
Residential proxy networks operate by converting compromised home devices into illicit exit nodes—essentially turning innocent users' internet connections into relay points for criminal traffic. Unlike datacenter proxies, which are easily identified and blocked by security systems, residential proxies use legitimate home IP addresses that blend seamlessly with normal user activity.
NetNut's operational model included:
The service operated across multiple domains, with netnut.com serving as its primary public-facing interface before being seized by the FBI.
## How the Network Functioned
NetNut worked by compromising devices and installing software that silently routed malicious traffic through the victim's home internet connection. Threat actors paid subscription fees to use these residential exit nodes for various attacks.
| Attack Vector | Description |
|---|---|
| Password Spraying | Distributed credential attacks appearing to originate from thousands of home addresses |
| Account Takeover | Access to victim infrastructure while masking their true location and origin |
| Web Scraping | Circumventing rate limiting and geographic restrictions |
| Reconnaissance | Scanning victim networks while appearing as residential traffic |
| Evasion | Bypassing security controls that block datacenter IP ranges |
According to Google's Threat Intelligence Group (GTIG), the scale of abuse was staggering: in a single week last month, GTIG observed 316 distinct threat clusters actively using suspected NetNut exit nodes, including both criminal and espionage-focused threat actors.
## The Disruption: A Multi-Agency Takedown
The operation brought together an unprecedented coalition of government agencies, technology companies, and infrastructure providers:
Google's response was comprehensive. The company:
1. Seized backend infrastructure: Disabled command-and-control (C2) servers that NetNut operators used to manage the botnet
2. Removed malicious applications: Used Google Play Protect to identify and disable apps containing NetNut proxy code
3. Automated user protection: Automatically warned affected Android users of infections
4. Shared intelligence: Distributed technical details about NetNut's SDKs and infrastructure to law enforcement, platform providers, and security researchers
5. Blocked account access: Terminated the accounts and services NetNut operators maintained on Google's infrastructure
## The Scale and Scope of Compromise
The 2 million devices across NetNut's network represents only the confirmed count—the actual compromised device base may be significantly larger. The geographic distribution and diversity of infected device types illustrate how pervasively residential proxy malware has penetrated consumer IoT ecosystems.
Device categories compromised:
Geographic reach: Global, with active C2 operations spanning multiple continents
Operator diversity: Hundreds of threat actors ranging from cybercriminal groups to sophisticated espionage organizations
## Implications for Organizations and Users
Organizations face significant risks from residential proxy networks, which enable threat actors to:
For consumer users, device compromise often occurs silently, with victims unaware their internet connection is being weaponized.
## Recommendations for Defense
For Enterprise Security Teams:
For Internet Service Providers:
For Device Manufacturers:
## HackWire Analysis
The NetNut disruption is tactically impressive but strategically incomplete—and the industry's structure virtually guarantees a resurgence. Here's what matters: the residential proxy market isn't a niche criminal service; it's become the backbone of modern abuse infrastructure, with hundreds of threat actors depending on it for everything from mundane credential attacks to sophisticated espionage operations. In a single week, 316 distinct threat clusters were actively routing traffic through NetNut alone.
But here's the critical insight that's being underreported: the proxy industry is essentially a fraud logistics network with built-in redundancy. When NetNut was disrupted, operators didn't go out of business—they simply pivoted to buying capacity from competitors. As Mandiant noted, the industry operates as a densely interconnected reseller network where botnet capacity constantly changes hands. Disrupting one large player redistributes demand to others rather than eliminating the underlying market.
The real impact of this operation isn't the temporary degradation of available proxy capacity. It's the intelligence harvest. Google shared technical details of NetNut's SDKs and C2 infrastructure with law enforcement and researchers—meaning the 316 threat clusters observed using NetNut can now be more accurately fingerprinted and tracked. That's worth more than the temporary disruption.
For defenders, the takeaway is unsettling: residential proxy abuse is now a mass-market attack capability. It's no longer confined to sophisticated actors. The barrier to entry is a subscription fee. Organizations need to treat distributed anomalous login attempts and scattered reconnaissance activity from residential IP ranges as a genuine threat class, not an edge case. Expect competitors and threat actors to intensify reliance on proxy networks as law enforcement disruptions temporarily tighten supply.
This also signals that Google's containment of Android malware—while valuable—has limits. Pre-installed malware and trojanized applications will continue to evade detection in the vast ecosystem of budget Android devices. — HackWire Editorial
## Related Coverage