Fraud Management & Cybercrime
,
Malware as-a-Service
,
Social Engineering

2 Million Home Devices, Including Routers and Smart TVs, Tied to NetNut Botnet

Mathew J. Schwartz (euroinfosec) •
July 3, 2026    

FBI Disrupts Widely Used NetNut Residential Proxy Service
Image: Shutterstock

The FBI and private-sector partners have disrupted NetNut, one of the world’s biggest and most popular residential proxy networks, which has been tied to routing and disguising online attacks and other malicious activity.

See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime

The FBI thanked Google, Lumen Technologies’ Black Lotus Labs and the Shadowserver Foundation for helping to facilitate the takedown, which included the seizure of multiple domain names and disrupting the botnet’s access to over 2 million home devices.

“We believe our coordinated actions have caused significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions,” said researchers at Google Threat Intelligence Group.

Malicious residential proxies press consumer devices into service and sell criminal subscribers the ability to route their traffic through these IP addresses, making them function as exit nodes. By routing traffic through an array of consumer devices all over the world, attackers can mask their malicious activity. This complicates network defenders’ ability to detect and block malicious activities.

“NetNut secretly hijacked over 2 million home devices like smart TVs and routers, allowing attackers to hide behind innocent users’ IP addresses. To put the scale of this threat into perspective, in a single week during June 2026, our team at GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups,” said Austin Larsen, principal threat analyst at Google Threat Intelligence Group, in a blog post.

Researchers said illicit customers of residential proxy networks use them to facilitate attacks against endpoints, to disguise their use of bulletproof services and legitimate infrastructure they’ve purloined for staging attacks, as well as for unleashing automated attacks, including password-spraying campaigns.

The botnets driving such services depend on scale. “A robust residential proxy network requires the control of millions of residential IP addresses to sell to customers for use. IP addresses in countries such as the U.S., Canada and Europe are considered especially desirable,” Google researchers said.

To build and maintain the NetNut botnet, its operators distribute software development kits with code designed to infect many different types of devices, including smart TVs and streaming boxes. Cybersecurity researchers have also tied the use of NetNut to the spread of variants of Mirai malware, used to build botnets for unleashing on-demand, distributed-denial-of-service attacks.

Google said it “also identified NetNut botnet plugin components for large-scale botnets such as Badbox 2.0,” referring to a China-based operation tied last year to the infection of over 1 million off-brand Android smart devices globally, including TV streaming devices, home projectors, digital picture frames and car infotainment systems (see: FBI Warns of Badbox 2.0 Botnet Surge in Chinese Devices).

“Cybercriminals gain unauthorized access to home networks by either configuring the product with malicious software prior to the user’s purchase or infecting the device as it downloads required applications that contain backdoors, usually during the set-up process,” the FBI said in a March 2025 alert.

In some cases, attackers trick users into installing software “in exchange for ‘unused bandwidth’ or ‘sharing your internet,'” Google said.

NetNut is operated by the publicly traded Israeli company Alarum Technologies, as cybersecurity reporter Brian Krebs first reported last month. The firm said Thursday it’s cooperating with investigators. “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Omer Weiss, legal counsel for Alarum Technologies, told Krebs.

In recent weeks, multiple security firms have reported that NetNut appears to be tied to the Popa botnet, designed to deliver residential proxy services, which is tied to the Vo1d botnet, which shares command-and-control infrastructure with the Badbox botnet.

Cybersecurity firm Qurium said in a June 19 report: “Popa has been found as a plugin component associated with the Vo1d botnet, a large-scale malware campaign targeting Android-based TV boxes and similar devices. Rather than being the entire malware itself, Popa functions as a networking layer that provides tunneling capabilities.”

Ongoing Disruptions

The disruption of NetNut followed the January takedown, led by Google, of IPIDEA, then one of the world’s largest residential proxy networks and NetNut’s principal competitor (see: Beyond Intel Sharing: The Push Toward Cyber Disruption).

As with many cybercrime takedowns, disrupting one service often drives users to embrace alternatives, and security experts said residential proxy network offerings continue to expand, providing additional failover options for subscribers.

Google said better threat-intelligence sharing and more decisive blocking, including by internet service providers and mobile platforms, will be required to arrest the malicious command-and-control infrastructure powering residential proxy networks.

“Creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers,” Google threat researchers said.