Google and FBI Kneecap NetNut's 2 Million-Device Proxy Botnet
Another day, another botnet disruption. This time the target was NetNut, one of the more widely used residential proxy networks, which has been significantly degraded by a coalition including Google, Lumen, Shadowserver, and the FBI. It follows a similar operation against IPIDEA back in January, suggesting this is now a sustained campaign rather than a one-off.
According to Google's Threat Intelligence Group (GTIG), NetNut had roped at least 2 million devices into its botnet, mostly cheap TV-streaming boxes. The network distributed its own SDK through these devices, quietly recruiting them as exit nodes. Classic stuff.
If you've ever wondered why anyone would voluntarily install such software, proxy providers typically dress it up as a bandwidth monetisation scheme. Let our app run in the background, get paid a trickle of cash. What could go wrong? Quite a lot, as it turns out, including feeding infrastructure that cybercriminals actively rely on and opening your home network to potential secondary vulnerabilities.
NetNut wasn't just selling residential proxies either. It offered mobile and datacenter proxies, various scraping tools, datasets, and crucially, a reseller programme. GTIG believes a number of other residential proxy networks were effectively running on NetNut's infrastructure underneath. That reseller layer is what makes this disruption potentially more painful for the broader ecosystem than a straightforward takedown.
That said, Google is managing expectations. After IPIDEA was disrupted in January, operators simply started buying capacity from rivals, morphing from network operators into resellers almost overnight. The ecosystem is fluid enough that degrading one provider doesn't automatically collapse the whole market.
'We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers,' GTIG said.
The scale of abuse running through NetNut was considerable. In a single week during June 2026, GTIG tracked 316 distinct threat clusters using suspected NetNut exit nodes, spanning both cybercriminal gangs and espionage groups. Uses included masking origin IPs when accessing victim environments, managing their own infrastructure without attribution, and running password spray attacks.
NetNut's involvement doesn't stop at proxy services either. GTIG found plugin components associated with Badbox 2.0, one of the larger botnet families currently active, and separate reports have flagged connections to Mirai variant infections.
There is one slightly awkward footnote. While netnut.com now displays a seizure notice, netnut.io remains live. The Register asked Google why. No reply yet.
Residential proxy networks occupy a legal grey zone. They're not inherently illegal and are marketed under privacy and freedom-of-expression angles. The trouble is that those same properties make them extremely convenient for anyone who wants to route malicious traffic through innocent residential IP addresses. The legitimacy of the business model and the illegitimacy of its heaviest users are two things that coexist rather comfortably.
Google's broader message is that these periodic disruptions, while useful, aren't a long-term fix. Sustained impact would need ISPs, mobile platforms, and device manufacturers all pulling in the same direction. Whether that coordination actually materialises is another question entirely.