Google and FBI dismantle NetNut proxy network on streaming devices
Google and the FBI have initiated a coordinated operation to disrupt NetNut, a residential proxy network accused of weaponizing IoT devices, including smart TVs and streaming boxes, as internet relays. The action involved disabling command-and-control infrastructure and using Play Protect to identify apps utilizing the network's SDKs to mask malicious traffic.
Key Takeaways
- Operation targeted infrastructure spanning 2 million home devices, many being uncertified Android streaming boxes with pre-installed proxy code.
- Google's Threat Intelligence Group identified 316 distinct threat clusters, including espionage groups, using NetNut nodes in a single week in June.
- The FBI seized several core NetNut domains while Google disabled command-and-control accounts used to manage the distributed relay network.
- NetNut is owned by Alarum Technologies, a Nasdaq-listed Israeli firm, which reported 64% revenue growth to $11.7M in Q1 2026.
Why It Matters
The crackdown highlights a critical security vulnerability in the low-cost streaming hardware market, where uncertified Android devices act as Trojan horses for global botnet infrastructure. For streaming providers, these proxy networks complicate audience measurement and bot detection by making automated traffic indistinguishable from legitimate residential viewing. The disruption of a Nasdaq-listed firm's core infrastructure signals an aggressive regulatory shift where commercial 'bandwidth sharing' services are increasingly treated as criminal botnets. Stakeholders should monitor Alarum Technologies' forthcoming SEC filings for financial impacts and potential legal liability as the FBI investigation continues.
Additional Context
The NetNut disruption follows a series of joint industry and law enforcement actions targeting the 'residential proxy' economy, which increasingly relies on the streaming ecosystem for scale. In July 2025, Google filed a lawsuit in New York federal court against the operators of Badbox 2.0 per Google Security Blog. That botnet compromised over 10 million uncertified Android devices, using them for large-scale ad fraud and creating 'residential proxies' without user consent. These low-cost devices often bypass official Android security protocols, making them ideal hosts for persistence layers like the 'Popa' botnet, which researchers recently linked back to NetNut infrastructure per KrebsOnSecurity and Qurium Media Foundation in June 2026. Technological analysis from Nokia Deepfield in June 2026 reported that residential proxy capacity now rivals major transit networks, fueled by a multi-billion-dollar demand for residential IP addresses used in AI training and web scraping. While NetNut's parent company, Alarum Technologies, maintains that its SDKs facilitate consensual bandwidth sharing, researchers at Synthient reported in June 2026 that none of the 20 examined apps bundled with the proxy code showed a consent prompt to users. This systemic lack of transparency in the Android app and hardware supply chain has forced ISPs and platforms like Google to use automated tools like Play Protect to proactively disable thousands of apps identified as 'stealth' relays.
Read full article at siliconangle.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source