CyberSecurityBoardThreat Intel · CVEs · Products
Cyber News

Google Disrupts NetNut Residential Proxy Network with 2 Million Home Devices

July 2, 2026

Google’s Threat Intelligence Group (GTIG), in collaboration with the FBI, Lumen, and other partners, has significantly disrupted NetNut, a massive residential proxy network that turns home devices into rented relays for malicious traffic. NetNut, also known as Popa, is estimated to control at least 2 million devices worldwide, including smart TVs and streaming boxes. These devices act as exit nodes, allowing attackers to route traffic through home internet connections to evade security tools.

Google reported that in a single week in June, 316 distinct threat clusters used suspected NetNut exit nodes for activities like password-guessing attacks. The network is owned by publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). Researchers from Qurium, Synthient, Nokia Deepfield, and Spur linked Popa to NetNut, with Synthient demonstrating that traffic sent into NetNut’s commercial gateway exited through a device enrolled in Popa. Alarum rejects the botnet label, claiming its software is for consented bandwidth-sharing, but researchers found that none of the over 20 apps examined showed users a consent prompt.

Google describes this as a degradation rather than a kill, as NetNut’s reseller program allows many seemingly independent proxy brands to resell the same pool. Previous actions against similar networks like IPIDEA and Badbox 2.0 showed these networks can be resilient. Google advises consumers to avoid apps offering payment for unused bandwidth, stick to official app stores, check app permissions, keep Google Play Protect enabled, and buy streaming hardware from known manufacturers.

CVEs: CVE-2026-20245

Malware: Mirai, Badbox 2.0

Companies: Google, Alarum Technologies, Lumen, Qurium, Synthient, Nokia Deepfield, Spur

Service providers: NetNut