Google, FBI Disrupt NetNut Residential Proxy Botnet
Google says it degraded the NetNut network by millions of devices; researchers tie the botnet to Israeli firm Alarum Technologies, which disputes the 'botnet' label.

On this page
Key takeaways
- Google, the FBI and Lumen coordinated to disrupt the NetNut (Popa) residential proxy network.
- Google estimates the network spans at least 2 million hijacked consumer devices worldwide.
- Google disabled the botnet's command-and-control accounts and flagged NetNut apps via Play Protect.
- In one week in June 2026, Google saw 316 distinct threat clusters using NetNut exit nodes.
- Researchers tie NetNut to Israeli firm Alarum Technologies, which rejects the 'botnet' characterization.
What to do now
Medium urgency- Avoid apps that pay for 'unused bandwidth' or 'sharing your internet'.
- Install apps only from official stores and review VPN/proxy permissions.
- Keep Google Play Protect enabled and buy Play Protect-certified devices.
- For enterprises, monitor DNS for residential-proxy indicators and limit untrusted consumer streaming hardware on corporate networks.
Google, in coordination with the FBI, internet carrier Lumen and other partners, has taken action to disrupt NetNut - also tracked as Popa - a sprawling residential proxy network that Google estimates is built on at least 2 million hijacked consumer devices such as smart TVs and streaming boxes. The company says the operation degraded the network and cut the operator's available device pool by millions.
Residential proxy networks route attacker traffic through the home IP addresses of ordinary device owners, hiding malicious activity behind trusted residential connections - and Google says NetNut was rented to both cybercriminal and state-linked espionage groups.
A coordinated Google, FBI and Lumen operation disrupted the NetNut residential proxy botnet, degrading a network of millions of hijacked consumer devices used to mask cyberattacks.
Google and law-enforcement partners disrupted NetNut/Popa, a residential proxy network of 2M+ hijacked smart TVs and streaming boxes rented to attackers. Google disabled its C2 accounts and used Play Protect against related apps. Researchers link NetNut to Alarum Technologies, which disputes the botnet label.
Affected & context
Google, working with the FBI, Lumen and other partners, took coordinated action against NetNut (also known as Popa), a large residential proxy network that Google estimates spans at least 2 million hijacked consumer devices worldwide and was rented to cybercriminal and espionage groups.
Residential proxy networks let attackers route malicious traffic through the home IP addresses of unsuspecting device owners, masking their origin and turning consumer smart TVs and streaming boxes into infrastructure for password-spray attacks, victim-environment access and data scraping.
Owners of infected consumer devices such as smart TVs and streaming boxes globally, whose home connections were used as exit nodes; and organizations whose environments were accessed by threat actors hiding behind NetNut proxies.
- Products
- Unofficial Android-based TV boxes and streaming devicesSmart TV apps (LG webOS, Samsung Tizen)NetNut residential proxy network
- Malware
- PopaVo1dBadbox 2.0Mirai (variants)
- Geography
- global
What Google and the FBI did
Google says it acted in coordination with the FBI, Lumen and other partners to disrupt NetNut, a residential proxy network also tracked as Popa. According to Google's Threat Intelligence Group (GTIG), the operation took three main steps:
- Disabled Google accounts and services that NetNut used for malware command-and-control (C2), which Google says violated its Terms of Service and Acceptable Use Policy.
- Shared technical intelligence on NetNut's SDKs and backend C2 infrastructure with platform providers, law enforcement and research firms.
- Used Google Play Protect to warn users about, and disable, applications known to incorporate NetNut SDKs, with continued protection against future install attempts.
Google described the result as significant degradation of NetNut's network and business operations, saying the action reduced the operator's available device pool by millions. The company framed the move as a continuation of its January 2026 disruption of the IPIDEA proxy network.
- Coordinated with the FBI, Lumen and other partners
- C2 Google accounts disabled; Play Protect used against related apps
- Builds on the January 2026 IPIDEA disruption
What NetNut and Popa are
Residential proxy networks sell the ability to route internet traffic through IP addresses owned by ordinary internet service providers, letting customers mask activity behind residential connections. To build that pool, operators need code running on home devices to enroll them as exit nodes - sometimes pre-installed on cheap hardware, sometimes hidden inside apps users download without understanding what they consent to.
Google estimates the NetNut network at at least 2 million devices distributed worldwide. Independent tracking cited by KrebsOnSecurity puts NetNut's daily footprint at roughly 1.5 to 2.5 million distinct IP addresses, according to Lumen's Black Lotus Labs. GTIG says Popa is associated with large-scale botnets including Badbox 2.0, and security researchers describe Popa as a plugin component tied to the Vo1d malware campaign, which targets unofficial Android-based TV boxes. Public reports cited by Google also document NetNut being used to spread variants of the Mirai DDoS malware.
- Google estimate: at least 2 million devices worldwide
- Lumen: ~1.5-2.5 million distinct IPs per day
- Popa tied to Vo1d; associated with Badbox 2.0
How the network was abused
In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes - a group that Google says spans both cybercriminal and espionage actors. According to Google, these actors used NetNut to mask their origin IP addresses when accessing victim environments, reaching their own infrastructure, and running password-spray attacks.
The risk extends into the home. When a consumer device becomes an exit node, unauthorized traffic passes through it, and Google warns that bad actors can reach other private devices on the same home network. Owners can also find their legitimate traffic flagged or blocked as their home IP is abused.
Google also stresses the ecosystem effect: beyond selling under its own brand, NetNut runs a reseller program, and Google says it has high confidence that many popular residential proxy brands are whitelabeling the NetNut botnet - one reason the company says lasting disruption requires targeting several interconnected providers at once.
- 316 threat clusters seen using NetNut in one June week
- Used for origin masking and password-spray attacks
- Reseller/whitelabel program spreads NetNut across brands
Estimating residential proxy network size is difficult; the 2 million figure is Google's stated estimate, not a precise count.
The disputed attribution - and the operator's denial
The link between the Popa botnet and a named company comes primarily from investigative reporting, not Google's own advisory, and it is contested. According to KrebsOnSecurity, researchers from multiple security firms tied the Popa botnet to NetNut, a residential proxy provider owned by the publicly-traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR). Proxy-tracking firm Synthient assessed with high confidence that devices running Popa forward traffic for NetNut clients.
Alarum Technologies rejects that framing. In a statement to KrebsOnSecurity, the company called the researchers' assertions "demonstrably inaccurate assertions and flawed deductions rather than verified facts," and disputed that its SDKs turn user devices into malware-controlled systems, saying they facilitate consent-based bandwidth sharing and that NetNut applies KYC checks and misuse monitoring. Separately, a NetNut research executive linked to one of the control domains told KrebsOnSecurity that the Popa SDK was sold and licensed to third parties years ago and that neither he nor NetNut operates the infrastructure now described as Popa. Other researchers, such as Spur, have questioned how rigorous NetNut's customer-verification really is. These competing claims should be treated as an open dispute.
- Attribution to Alarum Technologies comes from research/press, not Google's advisory
- Alarum rejects the 'botnet' characterization
- A NetNut executive says the SDK was licensed to third parties years ago
What consumers and IT teams should do
Google's guidance focuses on prevention. Consumers should be wary of apps that offer payment for "unused bandwidth" or "sharing your internet," stick to official app stores, review the permissions requested by third-party VPNs and proxy apps, and keep Google Play Protect enabled. When buying connected hardware such as set-top boxes, choose reputable manufacturers and, for Android TV, confirm the device is Play Protect certified.
For IT and MSP teams, residential-proxy SDKs are also a workplace concern: reporting cited by KrebsOnSecurity notes these services frequently beacon from employee devices, and warns that if a proxy on your network is abused to attack a third party, incident responders may correctly identify your address space as the source. Consider monitoring DNS for known residential-proxy indicators, restricting untrusted streaming hardware and consumer smart-TV apps on corporate networks, and reviewing bring-your-own-device exposure.
- Avoid 'bandwidth-sharing' apps; use official app stores
- Keep Play Protect enabled; buy Play Protect-certified devices
- Enterprises should watch for proxy SDKs beaconing from BYOD
What happens next
Google cautions that point-in-time takedowns rarely end the problem. After the IPIDEA disruption, it says, individual networks proved resilient and operators simply bought capacity from competitors - effectively becoming resellers. Google says durable results require scaling enforcement across the interconnected providers that resell and whitelabel each other's pools, and it plans to keep monitoring how NetNut's peers adapt. Watch for follow-on law-enforcement actions, further researcher reporting on NetNut's recovery or migration, and any formal response or filings from Alarum Technologies.
- Networks proved resilient after the IPIDEA takedown
- Google plans to target interconnected proxy providers
Timeline
Badbox 2.0 disruption
Google, HUMAN Security and Trend Micro disrupted Badbox 2.0, a botnet closely associated with Vo1d; many domains controlling Popa were seized around this time, per Qurium's reporting.
Source: KrebsOnSecurity
Confidence: Medium
IPIDEA proxy network disrupted
Google and partners disrupted the IPIDEA residential proxy network, the operation the NetNut action builds upon.
Source: Google Threat Intelligence Group
Confidence: High
Popa linked to Alarum Technologies
KrebsOnSecurity reported that researchers from multiple firms tied the Popa botnet to NetNut, a proxy provider owned by publicly-traded Israeli firm Alarum Technologies (NASDAQ: ALAR).
Source: KrebsOnSecurity
Confidence: Medium
NetNut disruption announced
Google announced coordinated action with the FBI, Lumen and others against NetNut, saying it degraded the network by millions of devices.
Source: Google Threat Intelligence Group
Confidence: High
Coverage published
SecurityWeek reported on the NetNut disruption and the network's estimated 2 million-plus infected devices.
Source: SecurityWeek
Confidence: High
Impact
A coordinated disruption degraded a residential proxy network of at least 2 million hijacked consumer devices used by cybercriminal and espionage actors. The action reduces the operator's device pool, but Google warns the fluid reseller ecosystem can recover, and the corporate attribution is contested.
Business impact
Organizations may see reduced abuse routed through NetNut IPs, but residential-proxy exposure on corporate networks remains a broader, ongoing risk.
Technical impact
Disabling of C2 accounts and Play Protect enforcement degrade the botnet's backend and app-based recruitment, though not necessarily every variant or reseller.
Security impact
A major infrastructure layer used to mask password-spray attacks, victim-environment access and data scraping was disrupted.
Privacy impact
Hijacked home devices routed third-party traffic through owners' connections, exposing home networks and risking misattribution of malicious activity to innocent users.
Affected audience: Owners of infected smart TVs, streaming boxes and other consumer devices, Organizations targeted by attackers hiding behind residential proxies, IT and MSP teams managing BYOD and network egress risk
Action required.
Technical details
- Attack vector
- Consumer devices are enrolled as proxy exit nodes via malicious or bundled SDKs in streaming boxes and apps; attackers then route traffic through them to mask origin.
Indicators of compromise
- Domain
gmslb[.]netPopa control domain identified by Qurium
Source: KrebsOnSecurity / Qurium
Confidence: Medium
- Domain
safernetwork[.]ioPopa control domain identified by Qurium
Source: KrebsOnSecurity / Qurium
Confidence: Medium
- Domain
tera-home[.]comPopa control domain identified by Qurium
Source: KrebsOnSecurity / Qurium
Confidence: Medium
- Domain
ninjatech[.]ioReused Popa control domain identified by Qurium
Source: KrebsOnSecurity / Qurium
Confidence: Medium
Detection methods
- Monitor DNS/network telemetry for known residential-proxy control domains and indicators.
- Use Google Play Protect to detect and disable apps embedding NetNut SDKs.
Mitigations
- Keep Play Protect enabled and remove untrusted 'bandwidth-sharing' apps.
- Restrict unofficial Android TV boxes and consumer smart-TV apps on corporate networks.
Technical references
Response
Vendor statement
Alarum Technologies, the parent company of NetNut, rejected the reports' characterization of its SDKs as a 'botnet,' saying the technology facilitates consent-based bandwidth sharing and that NetNut applies KYC checks and misuse monitoring. A NetNut executive said the Popa SDK was sold and licensed to third parties years ago and that neither he nor NetNut operates the infrastructure described as Popa.
Customer guidance
Google urges users to avoid 'bandwidth-sharing' apps, use official app stores, review VPN/proxy permissions, keep Play Protect enabled, and buy Play Protect-certified devices.
Response status: Acknowledged
FAQ
What is NetNut / Popa?
NetNut (also tracked as Popa) is a residential proxy network that routes customers' internet traffic through IP addresses of hijacked consumer devices such as smart TVs and streaming boxes. Google estimates it spans at least 2 million devices worldwide.
Who disrupted the network?
Google says it acted in coordination with the FBI, internet carrier Lumen and other partners, disabling command-and-control accounts, sharing intelligence, and using Google Play Protect against apps that embed NetNut SDKs.
Is NetNut linked to a specific company?
Investigative reporting by KrebsOnSecurity says researchers from multiple firms tied NetNut to Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Alarum rejects the 'botnet' characterization and says its SDKs enable consent-based bandwidth sharing. The attribution is disputed and does not come from Google's own advisory.
How do I know if my device is affected?
Risk is highest with unofficial Android TV boxes and apps that offer payment for 'sharing your internet.' Keep Google Play Protect enabled, install only from official stores, review VPN/proxy app permissions, and for Android TV confirm the device is Play Protect certified.
Does this end the residential-proxy threat?
No. Google warns these networks are resilient and interconnected - operators often buy capacity from competitors after a takedown. Google says lasting disruption requires targeting multiple providers, and it will keep monitoring the ecosystem.
The bottom line
Google, the FBI and Lumen disrupted NetNut/Popa, a residential proxy network of at least 2 million hijacked consumer devices used to mask password-spray attacks, victim-environment access and data scraping, degrading the operator's device pool by millions.
A significant blow to one of the largest residential proxy networks - but the reseller-driven ecosystem is fluid, and the corporate attribution remains contested.
What happens next
Watch for follow-on law-enforcement action, researcher reporting on NetNut's recovery, and any formal response from Alarum Technologies.
What to do
Audit home and corporate networks for untrusted streaming hardware and 'bandwidth-sharing' apps, and keep Play Protect enabled.
Sources
Google Threat Intelligence Group · Jul 2, 2026 · Primary source
Claims supported
- Coordinated action with the FBI, Lumen and others against NetNut/Popa
- Estimated at least 2 million devices worldwide
- Disabled C2 Google accounts; used Play Protect; shared intelligence
- 316 distinct threat clusters observed in one week in June 2026
- Reseller/whitelabel program and ecosystem ripple effect
SecurityWeek · Jul 3, 2026
Claims supported
- Summary of the disruption and its scale
- NetNut rented to cybercriminal and espionage groups
- NetNut operator linked to Israeli firm Alarum Technologies (attributed)
KrebsOnSecurity · Jun 18, 2026
Claims supported
- Multiple research firms tie Popa to NetNut / Alarum Technologies (NASDAQ: ALAR)
- Alarum rejects the botnet characterization; NetNut executive denies operating the infrastructure
- Lumen Black Lotus Labs estimate of 1.5-2.5 million daily IPs
- Control domains and reseller/KYC concerns from Synthient, Qurium, Spur, Nokia Deepfield