Google Drains the Swamp: NetNut Proxy Network Disrupted
Quick answer
Google disrupts the massive NetNut residential proxy network, cutting off millions of hijacked devices used by attackers to hide their tracks. A win for the good guys.
Google just took a big bite out of the residential proxy swamp, this time targeting the NetNut network (also known as Popa). In coordination with the FBI and Lumen, they’ve drained a significant pool of malicious exit nodes. This follows their January takedown of IPIDEA, showing they’re not just splashing around—they’re serious about cleaning up the ecosystem.
What They Did
Google didn’t just send a cease-and-desist. They got their hands dirty with a multi-pronged attack:
- Account shutdowns: Disabled Google accounts and services used by NetNut for command-and-control (C2) operations.
- Intel sharing: Handed over technical details on NetNut’s SDKs and C2 infrastructure to platforms, law enforcement, and researchers.
- Play Protect enforcement: Android’s built-in security now automatically warns users and blocks apps containing NetNut SDKs.
These moves have reduced the available pool of devices by millions, putting a serious dent in NetNut’s operations. And since NetNut runs a whitelabel reseller program, this ripple effect is likely to hit many popular proxy brands that were secretly riding on their botnet.
Why This Matters
NetNut is one of the biggest residential proxy networks out there, with an estimated 2 million devices worldwide. These aren’t servers in a data center—they’re smart TVs, streaming boxes, and other home gadgets that users unknowingly enrolled by installing shady apps or buying pre-infected devices. Attackers then route their traffic through these home IPs to hide their tracks, launch password sprays, or even infect other devices on the same network.
In just one week in June 2026, Google observed 316 distinct threat clusters using NetNut exit nodes, including cybercriminal and espionage groups. That’s a lot of bad actors hiding behind your neighbor’s smart TV.
What You Can Do
Google’s advice is solid: be wary of apps that pay you for “unused bandwidth”—that’s a classic proxy recruitment tactic. Stick to official app stores, review permissions for VPNs and proxies, and keep Google Play Protect active. When buying connected devices, choose reputable manufacturers and check for Android TV certification.
The Bigger Picture
This isn’t a one-and-done. The residential proxy industry is a tangled swamp of interconnected botnets that get resold and repurposed. Google acknowledges that point-in-time disruptions are just one tool—they need ongoing coordination with ISPs, mobile platforms, and other tech companies to keep the pressure on. For developers, this is a reminder that even seemingly innocent SDKs can hide malicious intent. Always audit your dependencies and stay informed about the tools you integrate.
For more on how cloud platforms handle security, check out our Google Cloud review and Cloudflare Workers review.
Original announcement published on Google Cloud.