Google and FBI Knock Out NetNut Proxy Network Backed by Millions of Infected Devices
A joint operation involving Google, the FBI, and several other organisations has taken a significant bite out of NetNut, a residential proxy network built on the backs of more than two million compromised Android devices.
NetNut, also tracked under the name Popa, spread through trojanised apps and malware including the now-familiar Badbox 2.0. The infected hardware spans smart TVs and streaming boxes, the kind of low-cost kit that rarely sees a security update and sits forgotten behind someone's television for years. Perfect botnet fodder.
The network's operator has ties to Alarum Technologies Ltd, a publicly-traded Israeli company. Rather than using the infrastructure for a single purpose, NetNut rented proxy access to all comers, including cybercriminal groups and state-linked espionage outfits. In one week alone during June, Google logged 316 distinct threat clusters using NetNut to mask their locations during password-spray attacks and to burrow into victim environments.
Google's response was fairly comprehensive. The company killed off Google accounts being used for command-and-control, gutting the botnet's backend. Google Play Protect was updated to disable the malicious applications on infected devices, with automatic warnings pushed to affected users. Threat intelligence was shared with industry partners and law enforcement throughout.
"We believe our coordinated actions have caused significant degradation to NetNut's proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions," Google stated.
One wrinkle worth noting: NetNut wasn't just selling access under its own name. It also ran a white-label reseller programme, meaning other proxy brands were quietly selling access to the same botnet without their customers necessarily knowing it.
This takedown follows the disruption of IPIDEA back in January, and Google is under no illusion that these wins are permanent. The company has observed that when one botnet takes a hit, operators simply start buying capacity from rivals, effectively recycling the problem. The conclusion Google draws from this is fairly obvious: you have to go after multiple interconnected providers simultaneously, or you're just playing whack-a-mole with infrastructure that reconstitutes itself within weeks.