Skip to content
anavem.com logoanavem.com logo
MitigatedNetNut (Popa) residential proxy networkHigh severityNewsCybersecurity

Google, FBI Disrupt NetNut Residential Proxy Botnet

Google says it degraded the NetNut network by millions of devices; researchers tie the botnet to Israeli firm Alarum Technologies, which disputes the 'botnet' label.

On this page

Key takeaways

  • Google, the FBI and Lumen coordinated to disrupt the NetNut (Popa) residential proxy network.
  • Google estimates the network spans at least 2 million hijacked consumer devices worldwide.
  • Google disabled the botnet's command-and-control accounts and flagged NetNut apps via Play Protect.
  • In one week in June 2026, Google saw 316 distinct threat clusters using NetNut exit nodes.
  • Researchers tie NetNut to Israeli firm Alarum Technologies, which rejects the 'botnet' characterization.

What to do now

Medium urgency
  1. Avoid apps that pay for 'unused bandwidth' or 'sharing your internet'.
  2. Install apps only from official stores and review VPN/proxy permissions.
  3. Keep Google Play Protect enabled and buy Play Protect-certified devices.
  4. For enterprises, monitor DNS for residential-proxy indicators and limit untrusted consumer streaming hardware on corporate networks.

Google, in coordination with the FBI, internet carrier Lumen and other partners, has taken action to disrupt NetNut - also tracked as Popa - a sprawling residential proxy network that Google estimates is built on at least 2 million hijacked consumer devices such as smart TVs and streaming boxes. The company says the operation degraded the network and cut the operator's available device pool by millions.

Residential proxy networks route attacker traffic through the home IP addresses of ordinary device owners, hiding malicious activity behind trusted residential connections - and Google says NetNut was rented to both cybercriminal and state-linked espionage groups.

A coordinated Google, FBI and Lumen operation disrupted the NetNut residential proxy botnet, degrading a network of millions of hijacked consumer devices used to mask cyberattacks.

Google and law-enforcement partners disrupted NetNut/Popa, a residential proxy network of 2M+ hijacked smart TVs and streaming boxes rented to attackers. Google disabled its C2 accounts and used Play Protect against related apps. Researchers link NetNut to Alarum Technologies, which disputes the botnet label.

Affected & context

Event summary

Google, working with the FBI, Lumen and other partners, took coordinated action against NetNut (also known as Popa), a large residential proxy network that Google estimates spans at least 2 million hijacked consumer devices worldwide and was rented to cybercriminal and espionage groups.

Why it matters

Residential proxy networks let attackers route malicious traffic through the home IP addresses of unsuspecting device owners, masking their origin and turning consumer smart TVs and streaming boxes into infrastructure for password-spray attacks, victim-environment access and data scraping.

Who is affected

Owners of infected consumer devices such as smart TVs and streaming boxes globally, whose home connections were used as exit nodes; and organizations whose environments were accessed by threat actors hiding behind NetNut proxies.

Products
Unofficial Android-based TV boxes and streaming devicesSmart TV apps (LG webOS, Samsung Tizen)NetNut residential proxy network
Malware
PopaVo1dBadbox 2.0Mirai (variants)
Geography
global

What Google and the FBI did

Google says it acted in coordination with the FBI, Lumen and other partners to disrupt NetNut, a residential proxy network also tracked as Popa. According to Google's Threat Intelligence Group (GTIG), the operation took three main steps:

  • Disabled Google accounts and services that NetNut used for malware command-and-control (C2), which Google says violated its Terms of Service and Acceptable Use Policy.
  • Shared technical intelligence on NetNut's SDKs and backend C2 infrastructure with platform providers, law enforcement and research firms.
  • Used Google Play Protect to warn users about, and disable, applications known to incorporate NetNut SDKs, with continued protection against future install attempts.

Google described the result as significant degradation of NetNut's network and business operations, saying the action reduced the operator's available device pool by millions. The company framed the move as a continuation of its January 2026 disruption of the IPIDEA proxy network.

  • Coordinated with the FBI, Lumen and other partners
  • C2 Google accounts disabled; Play Protect used against related apps
  • Builds on the January 2026 IPIDEA disruption

What NetNut and Popa are

Residential proxy networks sell the ability to route internet traffic through IP addresses owned by ordinary internet service providers, letting customers mask activity behind residential connections. To build that pool, operators need code running on home devices to enroll them as exit nodes - sometimes pre-installed on cheap hardware, sometimes hidden inside apps users download without understanding what they consent to.

Google estimates the NetNut network at at least 2 million devices distributed worldwide. Independent tracking cited by KrebsOnSecurity puts NetNut's daily footprint at roughly 1.5 to 2.5 million distinct IP addresses, according to Lumen's Black Lotus Labs. GTIG says Popa is associated with large-scale botnets including Badbox 2.0, and security researchers describe Popa as a plugin component tied to the Vo1d malware campaign, which targets unofficial Android-based TV boxes. Public reports cited by Google also document NetNut being used to spread variants of the Mirai DDoS malware.

  • Google estimate: at least 2 million devices worldwide
  • Lumen: ~1.5-2.5 million distinct IPs per day
  • Popa tied to Vo1d; associated with Badbox 2.0

How the network was abused

In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes - a group that Google says spans both cybercriminal and espionage actors. According to Google, these actors used NetNut to mask their origin IP addresses when accessing victim environments, reaching their own infrastructure, and running password-spray attacks.

The risk extends into the home. When a consumer device becomes an exit node, unauthorized traffic passes through it, and Google warns that bad actors can reach other private devices on the same home network. Owners can also find their legitimate traffic flagged or blocked as their home IP is abused.

Google also stresses the ecosystem effect: beyond selling under its own brand, NetNut runs a reseller program, and Google says it has high confidence that many popular residential proxy brands are whitelabeling the NetNut botnet - one reason the company says lasting disruption requires targeting several interconnected providers at once.

  • 316 threat clusters seen using NetNut in one June week
  • Used for origin masking and password-spray attacks
  • Reseller/whitelabel program spreads NetNut across brands

Estimating residential proxy network size is difficult; the 2 million figure is Google's stated estimate, not a precise count.

The disputed attribution - and the operator's denial

The link between the Popa botnet and a named company comes primarily from investigative reporting, not Google's own advisory, and it is contested. According to KrebsOnSecurity, researchers from multiple security firms tied the Popa botnet to NetNut, a residential proxy provider owned by the publicly-traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR). Proxy-tracking firm Synthient assessed with high confidence that devices running Popa forward traffic for NetNut clients.

Alarum Technologies rejects that framing. In a statement to KrebsOnSecurity, the company called the researchers' assertions "demonstrably inaccurate assertions and flawed deductions rather than verified facts," and disputed that its SDKs turn user devices into malware-controlled systems, saying they facilitate consent-based bandwidth sharing and that NetNut applies KYC checks and misuse monitoring. Separately, a NetNut research executive linked to one of the control domains told KrebsOnSecurity that the Popa SDK was sold and licensed to third parties years ago and that neither he nor NetNut operates the infrastructure now described as Popa. Other researchers, such as Spur, have questioned how rigorous NetNut's customer-verification really is. These competing claims should be treated as an open dispute.

  • Attribution to Alarum Technologies comes from research/press, not Google's advisory
  • Alarum rejects the 'botnet' characterization
  • A NetNut executive says the SDK was licensed to third parties years ago

What consumers and IT teams should do

Google's guidance focuses on prevention. Consumers should be wary of apps that offer payment for "unused bandwidth" or "sharing your internet," stick to official app stores, review the permissions requested by third-party VPNs and proxy apps, and keep Google Play Protect enabled. When buying connected hardware such as set-top boxes, choose reputable manufacturers and, for Android TV, confirm the device is Play Protect certified.

For IT and MSP teams, residential-proxy SDKs are also a workplace concern: reporting cited by KrebsOnSecurity notes these services frequently beacon from employee devices, and warns that if a proxy on your network is abused to attack a third party, incident responders may correctly identify your address space as the source. Consider monitoring DNS for known residential-proxy indicators, restricting untrusted streaming hardware and consumer smart-TV apps on corporate networks, and reviewing bring-your-own-device exposure.

  • Avoid 'bandwidth-sharing' apps; use official app stores
  • Keep Play Protect enabled; buy Play Protect-certified devices
  • Enterprises should watch for proxy SDKs beaconing from BYOD

What happens next

Google cautions that point-in-time takedowns rarely end the problem. After the IPIDEA disruption, it says, individual networks proved resilient and operators simply bought capacity from competitors - effectively becoming resellers. Google says durable results require scaling enforcement across the interconnected providers that resell and whitelabel each other's pools, and it plans to keep monitoring how NetNut's peers adapt. Watch for follow-on law-enforcement actions, further researcher reporting on NetNut's recovery or migration, and any formal response or filings from Alarum Technologies.

  • Networks proved resilient after the IPIDEA takedown
  • Google plans to target interconnected proxy providers

Timeline

  1. Badbox 2.0 disruption

    Google, HUMAN Security and Trend Micro disrupted Badbox 2.0, a botnet closely associated with Vo1d; many domains controlling Popa were seized around this time, per Qurium's reporting.

    Source: KrebsOnSecurity

    Confidence: Medium

  2. IPIDEA proxy network disrupted

    Google and partners disrupted the IPIDEA residential proxy network, the operation the NetNut action builds upon.

    Source: Google Threat Intelligence Group

    Confidence: High

  3. Popa linked to Alarum Technologies

    KrebsOnSecurity reported that researchers from multiple firms tied the Popa botnet to NetNut, a proxy provider owned by publicly-traded Israeli firm Alarum Technologies (NASDAQ: ALAR).

    Source: KrebsOnSecurity

    Confidence: Medium

  4. NetNut disruption announced

    Google announced coordinated action with the FBI, Lumen and others against NetNut, saying it degraded the network by millions of devices.

    Source: Google Threat Intelligence Group

    Confidence: High

  5. Coverage published

    SecurityWeek reported on the NetNut disruption and the network's estimated 2 million-plus infected devices.

    Source: SecurityWeek

    Confidence: High

Impact

A coordinated disruption degraded a residential proxy network of at least 2 million hijacked consumer devices used by cybercriminal and espionage actors. The action reduces the operator's device pool, but Google warns the fluid reseller ecosystem can recover, and the corporate attribution is contested.

Business impact

Organizations may see reduced abuse routed through NetNut IPs, but residential-proxy exposure on corporate networks remains a broader, ongoing risk.

Technical impact

Disabling of C2 accounts and Play Protect enforcement degrade the botnet's backend and app-based recruitment, though not necessarily every variant or reseller.

Security impact

A major infrastructure layer used to mask password-spray attacks, victim-environment access and data scraping was disrupted.

Privacy impact

Hijacked home devices routed third-party traffic through owners' connections, exposing home networks and risking misattribution of malicious activity to innocent users.

Affected audience: Owners of infected smart TVs, streaming boxes and other consumer devices, Organizations targeted by attackers hiding behind residential proxies, IT and MSP teams managing BYOD and network egress risk

Action required.

Technical details

Attack vector
Consumer devices are enrolled as proxy exit nodes via malicious or bundled SDKs in streaming boxes and apps; attackers then route traffic through them to mask origin.

Indicators of compromise

Domain
gmslb[.]net

Popa control domain identified by Qurium

Source: KrebsOnSecurity / Qurium

Confidence: Medium

Domain
safernetwork[.]io

Popa control domain identified by Qurium

Source: KrebsOnSecurity / Qurium

Confidence: Medium

Domain
tera-home[.]com

Popa control domain identified by Qurium

Source: KrebsOnSecurity / Qurium

Confidence: Medium

Domain
ninjatech[.]io

Reused Popa control domain identified by Qurium

Source: KrebsOnSecurity / Qurium

Confidence: Medium

Detection methods

  • Monitor DNS/network telemetry for known residential-proxy control domains and indicators.
  • Use Google Play Protect to detect and disable apps embedding NetNut SDKs.

Mitigations

  • Keep Play Protect enabled and remove untrusted 'bandwidth-sharing' apps.
  • Restrict unofficial Android TV boxes and consumer smart-TV apps on corporate networks.

Technical references

Response

Vendor statement

Alarum Technologies, the parent company of NetNut, rejected the reports' characterization of its SDKs as a 'botnet,' saying the technology facilitates consent-based bandwidth sharing and that NetNut applies KYC checks and misuse monitoring. A NetNut executive said the Popa SDK was sold and licensed to third parties years ago and that neither he nor NetNut operates the infrastructure described as Popa.

Customer guidance

Google urges users to avoid 'bandwidth-sharing' apps, use official app stores, review VPN/proxy permissions, keep Play Protect enabled, and buy Play Protect-certified devices.

Response status: Acknowledged

FAQ

What is NetNut / Popa?

NetNut (also tracked as Popa) is a residential proxy network that routes customers' internet traffic through IP addresses of hijacked consumer devices such as smart TVs and streaming boxes. Google estimates it spans at least 2 million devices worldwide.

Who disrupted the network?

Google says it acted in coordination with the FBI, internet carrier Lumen and other partners, disabling command-and-control accounts, sharing intelligence, and using Google Play Protect against apps that embed NetNut SDKs.

Is NetNut linked to a specific company?

Investigative reporting by KrebsOnSecurity says researchers from multiple firms tied NetNut to Alarum Technologies Ltd (NASDAQ: ALAR), a publicly-traded Israeli firm. Alarum rejects the 'botnet' characterization and says its SDKs enable consent-based bandwidth sharing. The attribution is disputed and does not come from Google's own advisory.

How do I know if my device is affected?

Risk is highest with unofficial Android TV boxes and apps that offer payment for 'sharing your internet.' Keep Google Play Protect enabled, install only from official stores, review VPN/proxy app permissions, and for Android TV confirm the device is Play Protect certified.

Does this end the residential-proxy threat?

No. Google warns these networks are resilient and interconnected - operators often buy capacity from competitors after a takedown. Google says lasting disruption requires targeting multiple providers, and it will keep monitoring the ecosystem.

The bottom line

Google, the FBI and Lumen disrupted NetNut/Popa, a residential proxy network of at least 2 million hijacked consumer devices used to mask password-spray attacks, victim-environment access and data scraping, degrading the operator's device pool by millions.

A significant blow to one of the largest residential proxy networks - but the reseller-driven ecosystem is fluid, and the corporate attribution remains contested.

What happens next

Watch for follow-on law-enforcement action, researcher reporting on NetNut's recovery, and any formal response from Alarum Technologies.

What to do

Audit home and corporate networks for untrusted streaming hardware and 'bandwidth-sharing' apps, and keep Play Protect enabled.

Sources

  1. Google Threat Intelligence Group · Jul 2, 2026 · Primary source

    Claims supported
    • Coordinated action with the FBI, Lumen and others against NetNut/Popa
    • Estimated at least 2 million devices worldwide
    • Disabled C2 Google accounts; used Play Protect; shared intelligence
    • 316 distinct threat clusters observed in one week in June 2026
    • Reseller/whitelabel program and ecosystem ripple effect
  2. SecurityWeek · Jul 3, 2026

    Claims supported
    • Summary of the disruption and its scale
    • NetNut rented to cybercriminal and espionage groups
    • NetNut operator linked to Israeli firm Alarum Technologies (attributed)
  3. KrebsOnSecurity · Jun 18, 2026

    Claims supported
    • Multiple research firms tie Popa to NetNut / Alarum Technologies (NASDAQ: ALAR)
    • Alarum rejects the botnet characterization; NetNut executive denies operating the infrastructure
    • Lumen Black Lotus Labs estimate of 1.5-2.5 million daily IPs
    • Control domains and reseller/KYC concerns from Synthient, Qurium, Spur, Nokia Deepfield
Reader actions
Was this helpful?
Rate this articleRate
4 readers viewed this article

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.