Google and FBI dismantle NetNut proxy network of 2 million devices
Google and the FBI have disrupted the NetNut residential proxy network, which utilized over 2 million infected consumer devices, including smart TVs and streaming boxes, as exit nodes for malicious traffic. The operation involved domain seizures, Google account terminations, and the use of Google Play Protect to disable applications containing the malicious NetNut SDK.
Key Takeaways
- Over 2 million devices globally were infected to serve as exit nodes for cybercriminal and espionage traffic.
- Google observed 316 distinct threat clusters utilizing NetNut exit nodes in a single week during June 2026.
- The FBI seized hundreds of domains, including netnut.com, while primary operator Alarum Technologies suspended operations to investigate.
- The disruption targeted the commercial reseller model, where proxy providers buy and white-label botnet capacity from competitors.
Why It Matters
The hijacking of smart TVs and streaming boxes at this scale highlights a critical vulnerability in the streaming device supply chain, where off-brand hardware and side-loaded apps are repurposed as ‘clean’ residential exit nodes. For streaming platforms, this infrastructure bypasses traditional data-center blocklists, enabling credential stuffing, account takeover, and ad fraud that looks like authentic home user traffic. The inclusion of a publicly traded parent company, Alarum Technologies, suggests that commercial proxy providers are increasingly moving from gray-market operations into structural dependency on botnet-style device enrollment. Watch for whether Alarum’s voluntary suspension of data traffic leads to a wider shift toward regulated, auditable enterprise proxy services versus fragmented, opaque reseller networks.
Additional Context
The NetNut disruption follows a series of recent takedowns targeting the residential proxy ecosystem. Per Security Sector reporting in January 2026, Google and its partners previously dismantled IPIDEA, another massive residential proxy network. That operation revealed the interconnected nature of the market, as operators whose botnets are degraded frequently purchase spare capacity from rival networks to maintain service, effectively becoming resellers of their competitors' infrastructure. This reseller dynamic complicates long-term suppression, as enforcement against one brand doesn't necessarily remove the underlying compromised devices from the global liquidity pool. Regulatory and law enforcement focus on these networks has sharpened throughout 2026. In March 2026, the FBI issued a FLASH alert naming 18 specific router models frequently hijacked by the AVrecon malware to feed the SocksEscort proxy service. According to that advisory, threat actors exploit unpatched vulnerabilities in SOHO routers and IoT devices to maintain remote shells, facilitating ad fraud and password-spraying cycles. This trend aligns with a broader April 2026 warning from CISA and international partners regarding China-nexus actors, who have reportedly shifted away from individually procured infrastructure toward large-scale, externally provisioned covert networks like 'Raptor Train' to obfuscate attribution and gain deniable access to victim environments. Technical enforcement is also moving toward the device layer. In the NetNut case, the use of Google Play Protect to disable infected apps represents a growing trend of platform-level intervention. As reported by Infosecurity Magazine in July 2026, the hijacking of inexpensive, off-brand Android-based smart TVs often occurs through deceptive SDKs embedded in unofficial streaming clients. This creates a persistent challenge for defenders: while domain seizures impose access friction, durable remediation requires clearing malware from millions of unmanaged consumer endpoints that lack standard endpoint detection and response (EDR) tools.
Read full article at debuglies.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source