FBI and Google dismantle NetNut botnet hijacking 2 million streaming devices
The FBI and Google have dismantled the NetNut residential proxy network, which exploited trojanized IPTV and streaming apps to turn 2 million consumer streaming devices into high-trust exit nodes for cybercriminals. The joint operation involved seizing domains, disabling Google service abuse, and utilizing Google Play Protect to block malicious SDKs from further compromising home networks.
Key Takeaways
- NetNut secretly enrolled approximately 2 million devices, serving 316 distinct cybercriminal and espionage clusters in one week this June.
- The network utilized trojanized IPTV apps and streaming utilities to hijack smart TVs and Android boxes without user consent.
- Google Play Protect was updated to automatically detect and block applications containing hidden NetNut software development kits.
- The FBI seized several domains including netnut.com and proxyjet.io, while the IRS Criminal Investigation division joined the enforcement effort.
- Alarum Technologies, the publicly traded Israeli firm behind NetNut, stated it is cooperating with law enforcement following the domain seizures.
Why It Matters
The disruption highlights a critical vulnerability in the streaming supply chain where low-cost hardware and unofficial apps serve as Trojan horses for high-trust residential proxy networks. For platform operators and advertisers, these exit nodes allow malicious actors to bypass standard IP-based fraud detection by appearing as legitimate domestic traffic. While this action degrades NetNut’s capacity, the ecosystem’s highly resilient reseller model means demand will likely migrate to other stealth providers who white-label similar hijacked pools. Industry observers should watch for updates to Android TV certification standards and potential downward pressure on Alarum Technologies’ (NASDAQ: ALAR) valuation as legal and regulatory scrutiny intensifies.
Additional Context
The dismantling of NetNut follows a pattern of increasingly aggressive U.S. law enforcement targeting the commercial residential proxy market. In May 2024, the Department of Justice announced the disruption of the 911 S5 botnet, which infected over 19 million IP addresses across 200 countries. Per the DOJ, that network enabled roughly $5.9 billion in fraudulent pandemic relief claims. Similar to NetNut, 911 S5 operated by bundling malicious code with 'free' VPN services and pirated software, turning consumer Windows systems into relays for cybercriminals. More recently, Google's Threat Intelligence Group (GTIG) has shifted toward a multi-pronged enforcement strategy to counter market resilience. In January 2026, Google disrupted IPIDEA, a major China-based competitor to NetNut that automated traffic masking for over 550 threat groups. Despite these efforts, researchers at Bitsight noted that proxy operators often recover capacity within days by purchasing bandwidth from rivals. Google has acknowledged that lasting disruption requires targeting the shared infrastructure of multiple, interconnected providers simultaneously rather than treating each botnet as an isolated case. The financial impact on NetNut’s parent company, Alarum Technologies, remains a focal point for investors. In May 2026, Alarum reported a 64% year-over-year revenue increase to $11.7 million, citing strong demand for its AI data collection infrastructure. However, the revelation that its residential proxy pool relies on non-consensual device enrollment via trojanized apps could jeopardize the firm's standing as a legitimate AI data provider. According to recent reporting by KrebsOnSecurity, security researchers have long linked Alarum’s software to the Popa botnet, suggesting that the recent FBI domain seizures are part of a broader crackdown on the 'gray market' for high-reputation consumer IP addresses.
Read full article at techtimes.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source