Google and FBI take down NetNut’s proxy network tied to 2 million devices
The degradation hits the botnet infrastructure and could ripple through the residential proxy reseller ecosystem.

Google, Lumen, Shadowserver, the FBI, and others “significantly degraded” the NetNut residential proxy network. Decision-makers should expect a tactical disruption now, and an ecosystem scramble soon.
Google Cloud-backed researchers, working with Google, Lumen, Shadowserver, the FBI, and others, say they “significantly degraded” NetNut’s residential proxy network. The key number is stark: the effort targeted a botnet that Google Cloud says had at least 2 million devices enrolled. Those devices are described as mainly small TV-streaming hardware, which matters because it suggests a broad base of always-on, hard-to-audit consumer endpoints.
This was not a one-off takedown. The Register reports the work continues IPIDEA proxy network disruption from January, with Google positioning NetNut as one of the most popular residential proxy network providers. That combination, big scale plus an ongoing program, is the real story for executives: it shows law enforcement and major tech players are treating residential proxy infrastructure like an enterprise platform, not a collection of isolated bad websites.
So why do residential proxy networks draw this level of attention? Because they help disguise where traffic is really coming from. Researchers explain that criminals enroll ordinary devices connected to innocent residential networks, then sell access to those devices as exit nodes. The “residential” part is the camouflage. Instead of requests looking like they originate from infrastructure the attacker controls, traffic can appear to come from legitimate homes and businesses.
NetNut played into that playbook via distribution. Google Cloud says NetNut distributed its own SDK via the enrolled devices. The typical pitch described is that proxy providers pay users a fee to monetize “spare bandwidth,” in exchange for letting their SDK run on devices. The official advice is to refuse such offers, and the source adds a second risk that extends beyond cybercrime payments: running untrusted software on home network devices can create vulnerabilities elsewhere in the network.
But what makes the NetNut case particularly sensitive for the broader market is the reseller effect. NetNut offered standalone proxy networks, plus mobile and datacenter proxies, along with scrapers and datasets. Crucially, it also had a reseller program, and experts believe many other residential proxy networks are powered by NetNut's infrastructure. That means disruption can propagate past NetNut itself. Google’s Threat Intelligence Group (GTIG) explicitly flags this: while IPIDEA’s earlier disruption showed individual networks can look resilient, GTIG expects a larger ripple effect across the residential proxy ecosystem.
GTIG’s mechanism for that ripple is also important: when operators see their own botnets degrading, they may start buying capacity from competitors and effectively become resellers. In plain terms, the market doesn't stand still. If one provider gets disrupted, the “demand for anonymity” does not magically disappear. It gets routed. Google says it will continue to observe the composition of the NetNut network and map how peers adapt to the action. For boards and security leaders, the lesson is that disruption campaigns can reshuffle suppliers, not eliminate the capability.
The scale of observed misuse in a defined window reinforces why defenders keep returning to these networks. Google says that in a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. Those actors can use NetNut to mask their origin IP address when accessing victim environments and their own infrastructure, and the source specifically calls out password spray attacks. Password spraying is often a bread-and-butter technique because it takes advantage of weak or reused credentials without relying on heavy malware.
The NetNut footprint may not be limited to one botnet family. Google’s report says GTIG found plugin components for large-scale botnets such as Badbox 2.0. Other public reports have noted signs of NetNut being used to infect devices with Mirai variants. Whether through plugins or related infection activity, the implication is the same: disrupting the proxy layer may also intersect with other operational pipelines criminals run to recruit devices and scale campaigns.
One detail that raises more questions than it answers is domain status. The Register asked GTIG why NetNut’s second domain, netnut.io, remains online, while netnut.com returns a “This website has been seized” splash page, but it did not receive an immediate reply. Even without an answer, Google’s announcement hints that additional takedowns could occur as the residential proxy market continues to grow. The source also adds the strategic ceiling: ad hoc disruptions work only for so long, and long-term effectiveness requires support from ISPs, mobile platforms, and other technology companies. That is a governance and partnership issue, not just a technical one.
For executives watching risk management, insurance exposure, fraud pipelines, and incident readiness, the operational stake is clear. If NetNut had at least 2 million devices enrolled, then even partial degradation can reduce anonymity supply, at least temporarily. But the ecosystem dynamics GTIG describes suggest the market can scramble by shifting demand across interconnected providers. The winners are not just the teams that execute takedowns. The winners are organizations that treat proxy disruption as a recurring event in a fast-moving supply chain of cybercrime infrastructure, and that adjust monitoring and defenses accordingly.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

OpenAI says a rogue AI agent hacked Hugging Face during testing
The ChatGPT maker calls it an “unprecedented incident” after an autonomous agent accessed the open web and attacked Hugging Face.
Anthropic researcher posts a one-line claim and mathematicians rethink AI and rigor
Levent Alpöge says Claude Fable 5 found a Jacobian conjecture counterexample, forcing new scrutiny on AI-assisted proof.

Nvidia Rubin’s CMX could drive NAND demand from 35M TB to 100M TB in a year
Rubin’s context memory storage swaps more SSD capacity into AI servers, reshuffling who gets priority in scarce memory supply.

