← BACK TO FEED
botnetresidential proxiesGooglecybercrimeAndroid malware

Google and FBI Knock Out NetNut Proxy Network Backed by Millions of Infected Devices

Google, the FBI, and other partners disrupted NetNut (also known as Popa), a residential proxy network comprising over 2 million infected Android devices, including smart TVs and streaming boxes compromised through malicious apps. The network, linked to Israeli firm Alarum Technologies, rented proxy access to cybercriminals and espionage groups, with 316 distinct threat clusters observed using it in a single week. Google's actions included disabling associated accounts, dismantling backend infrastructure, and removing infected apps via Google Play Protect, resulting in a significant reduction in the botnet's available devices.

A joint operation involving Google, the FBI, and several other organisations has taken a significant bite out of NetNut, a residential proxy network built on the backs of more than two million compromised Android devices.

NetNut, also tracked under the name Popa, spread through trojanised apps and malware including the now-familiar Badbox 2.0. The infected hardware spans smart TVs and streaming boxes, the kind of low-cost kit that rarely sees a security update and sits forgotten behind someone's television for years. Perfect botnet fodder.

The network's operator has ties to Alarum Technologies Ltd, a publicly-traded Israeli company. Rather than using the infrastructure for a single purpose, NetNut rented proxy access to all comers, including cybercriminal groups and state-linked espionage outfits. In one week alone during June, Google logged 316 distinct threat clusters using NetNut to mask their locations during password-spray attacks and to burrow into victim environments.

Google's response was fairly comprehensive. The company killed off Google accounts being used for command-and-control, gutting the botnet's backend. Google Play Protect was updated to disable the malicious applications on infected devices, with automatic warnings pushed to affected users. Threat intelligence was shared with industry partners and law enforcement throughout.

"We believe our coordinated actions have caused significant degradation to NetNut's proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions," Google stated.

One wrinkle worth noting: NetNut wasn't just selling access under its own name. It also ran a white-label reseller programme, meaning other proxy brands were quietly selling access to the same botnet without their customers necessarily knowing it.

This takedown follows the disruption of IPIDEA back in January, and Google is under no illusion that these wins are permanent. The company has observed that when one botnet takes a hit, operators simply start buying capacity from rivals, effectively recycling the problem. The conclusion Google draws from this is fairly obvious: you have to go after multiple interconnected providers simultaneously, or you're just playing whack-a-mole with infrastructure that reconstitutes itself within weeks.

READ NEXT
Google and FBI Kneecap NetNut's 2 Million-Device Proxy BotnetDutch Authorities Axe 17-Million-Device Botnet Tied to Russian Proxy Firm23 Million Paidwork Users' Data Dumped Online After Alleged March Breach