- Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as Popa.
- The network controlled at least 2 million infected Android devices like smart TVs and streaming boxes worldwide, and criminals and hackers used it to hide their online attacks.
- The FBI seized multiple domains linked to NetNut as part of the ongoing investigation.
Google has dealt a significant blow to one of the world’s largest criminal proxy networks. The tech company worked together with the FBI, Lumen Technologies, and others to shut down NetNut residential proxy network.
The action, reported on July 2, involved the shutdown of a network that covertly turned common household devices into tools for cybercriminal activities.
According to Google, the action helped eliminate millions of hijacked devices from the list of available devices in the network.
What is NetNut and How Did It Work?
NetNut, also tracked as Popa, operated a massive network of infected consumer devices. As per Google’s Threat Intelligence Group, the number of affected devices in the network included at least two million devices powered by the Android operating system that were located all over the world. However, they were not limited only to regular personal computers or smartphones.
There are many more internet-enabled devices out there, including smart TVs, set-top boxes, and so forth.
The company built this network by hiding malicious software inside apps and other programs. Many devices became infected through trojanized applications that users downloaded without knowing what was hidden inside. Some devices even came with the malicious software already installed before people bought them.
Once compromised, these devices quietly routed internet traffic for paying customers. The owners had no idea that strangers were using their smart TV or streaming box for criminal activity. Experts refer to this type of service as a residential proxy network.
What Makes Residential Proxy Networks Dangerous?
Residential proxy services allow internet traffic to pass through home internet connections instead of data centers. Some companies offer these services for legitimate tasks like web testing or market research. However, cybercriminals soon learned how to use these devices to carry out some more nefarious tasks.
By connecting to these proxy networks, attackers can hide their true identity. This makes their malware activity appear like regular traffic since it’s coming from a regular user connection and not a hacking infrastructure. As a result, detecting and stopping their activities becomes very hard.
The severity of such attacks was demonstrated when unknown malware shut down National Health Service operations, highlighting the real-world impact of cybercrime.
The abuse occurred on a large scale. In just one week during June, Google observed 316 separate threat clusters using suspected NetNut exit nodes. These gangs included both cybercriminals and state-sponsored hackers. The cybercrime network was used for password spraying attacks, penetration of compromised servers, and concealment of the location of the hacking operation.
How Authorities Took Action
Google took several steps to dismantle the network. The company disabled Google accounts and services used to control parts of the infrastructure. This cut off NetNut’s ability to command and manage the infected devices. Google also shared technical findings with law enforcement and cybersecurity partners to support a wider investigation.
The company updated Google Play Protect to automatically warn users about applications known to include NetNut software. The system now disables these apps and blocks future installation attempts. This protects Android users from unknowingly joining the network.
The FBI joined the effort with its own enforcement actions. The bureau seized several domains connected to NetNut as part of the investigation. NetNut’s parent company, Israeli firm Alarum Technologies, stated that it had been notified regarding domain seizures. Alarum Technologies claims that it takes the issue seriously and will do everything in its power to cooperate with the authorities looking into possible misuse of its network.
In addition, Bloomberg independently learned that the FBI has investigated the relationship between NetNut and the Popa botnet for a year now. Investigators from multiple federal agencies reviewed the case during a meeting on proxy networks held in Colorado last year.
Part of a Wider Campaign Against Proxy Networks
The NetNut disruption is not Google’s first action against malicious residential proxy services. Earlier this year, the company announced a similar operation against IPIDEA, another large proxy network built on compromised devices.
That effort shut down at least 13 proxy brands and removed millions of infected devices from the network. Google also identified hundreds of Android apps and thousands of Windows files linked to IPIDEA’s infrastructure.
These operations show Google is expanding its campaign beyond individual malware families. The company is now targeting the infrastructure that enables large-scale cybercrime.
The latest action against NetNut appears to have significantly degraded the network’s operations. But Google warns that proxy networks can be resilient. When faced with disruption, operators often buy capacity from competitors to rebuild.
Why this Matters for Consumers
Residential proxy networks have become valuable tools for attackers. They disguise bad traffic so it looks like it’s coming from regular people at home.
That trick makes it much easier to steal logins, commit fraud, grab data, and get away with all sorts of online crime because it’s harder for security systems to spot them.
Shutting down NetNut cuts off a lot of those devices, which disrupts the entire operation. This makes it harder and more expensive for criminals to rent trusted residential internet connections.
This incident highlights the increasing dangers surrounding internet-enabled devices. Cyber criminals are now going after internet-enabled devices such as smart TVs, streamers, and other Android devices more than before.
The best way to avoid these risks? Keep your software updated, only download apps from places you trust, and don’t turn off any built-in security. Also, be very cautious about deals that offer you money for your unused bandwidth; they’re rarely as good, or as safe, as they sound. These are common ways malicious proxy networks grow.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...
Cybercriminal Claims Leak of Internal Visa Systems, but No Customer Data Exposed
A cybercriminal claims they have internal Visa system details, including authentication flows and AP...