Google’s Continued Disruption of Malicious Residential Proxy Networks
Google, with the FBI and Lumen, disrupted the NetNut residential proxy network, disabling associated Google accounts and services used for malware command and control. The action follows a January 2026 disruption of the IPIDEA proxy network.
Google Cloud Threat Intelligence, in coordination with the FBI, Lumen, and other partners, disabled Google accounts and services linked to the NetNut residential proxy network, also known as Popa, for violating Google’s Terms of Service. The disruption targeted malware command and control infrastructure, removing access to Google services used by NetNut. Technical intelligence on NetNut’s SDKs and backend infrastructure was shared with law enforcement, platform providers, and research firms to support broader ecosystem enforcement.
Google Play Protect, Android’s built-in security system, automatically warned users and disabled applications containing NetNut SDKs, preventing further installations. The disruption reduced NetNut’s available device pool by millions and targeted its reseller program, which allowed whitelabeling of the network. Google estimates NetNut’s botnet size at least 2 million devices, distributed globally, with components identified in large-scale botnets such as Badbox 2.0.
Residential proxy networks like NetNut sell access to millions of residential IP addresses, enabling attackers to mask malicious activity by hijacking ISP-owned IPs. Home devices become part of these networks through pre-installed malware or deceptive applications offering payment for "unused bandwidth." This exposes users to risks such as their legitimate traffic being flagged as suspicious or their home networks being accessed by unauthorized parties.
In June 2026, Google observed 316 threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. These actors used NetNut to mask their origin IPs during attacks, including password spray attempts and Mirai DDoS botnet infections. Google urges users to avoid third-party VPNs or proxy apps offering payments, review app permissions, and purchase devices from reputable manufacturers to mitigate risks.