Google, the FBI, and other partners disrupted NetNut (also known as Popa), a residential proxy network comprising over 2 million infected Android devices, including smart TVs and streaming boxes compromised through malicious apps. The network, linked to Israeli firm Alarum Technologies, rented proxy access to cybercriminals and espionage groups, with 316 distinct threat clusters observed using it in a single week. Google's actions included disabling associated accounts, dismantling backend infrastructure, and removing infected apps via Google Play Protect, resulting in a significant reduction in the botnet's available devices.