← All news

general

Google Disrupts NetNut, a 2M-Device Residential Proxy Network

2026-07-03

Google has taken a serious swipe at NetNut, a service that quietly turns ordinary home internet connections into rented relays for other people's traffic. Working with the FBI, Lumen and a handful of independent researchers, Google's Threat Intelligence Group says it has pulled millions of devices out of NetNut's usable pool.

Two million devices, mostly sitting in living rooms

The network, also tracked as Popa, spans at least two million devices worldwide. A lot of them are smart TVs and the cheap streaming boxes people plug in and forget about. Once enrolled, strangers can route their browsing through your connection, and your IP address wears the blame for whatever they get up to. That is precisely the appeal for buyers: traffic that looks like ordinary home browsing rather than the datacenter traffic that security tools tend to block on sight.

In one week in June alone, GTIG counted 316 distinct threat groups using suspected NetNut exit nodes to hide their location and run password-guessing attacks against other people's accounts. Some of the same hijacked devices have also turned up in familiar botnets like Mirai and Badbox 2.0, so the same TV in the corner of the room may be doing several jobs at once.

An unusual owner for this kind of network

What sets NetNut apart is that it does not trace back to a shadowy operator in a jurisdiction of convenience. Researchers at Qurium, Synthient, Nokia Deepfield and Spur linked Popa to NetNut, which is owned by Israeli firm Alarum Technologies, listed on NASDAQ as ALAR.

In a controlled test, Synthient sent traffic into NetNut's commercial gateway and then watched it come back out through a device Synthient itself had enrolled in Popa. Alarum rejects the botnet label and says its software runs on consented bandwidth-sharing agreements. Synthient, for its part, reported that of the more than 20 apps it examined in the network, none actually showed users a consent prompt before signing up their connection.

Degradation, not a kill

Google is careful about the language. This is a degradation, not a shutdown. NetNut runs a reseller programme, which means a long list of seemingly independent proxy brands are quietly reselling access to the same underlying pool. When one operator gets squeezed, the others buy capacity from rivals and the traffic quietly reappears somewhere else on the map.

For the average household, the tell is simpler than any of this suggests. Apps that offer to pay you a few dollars a month for your unused bandwidth are almost always the front door for a service like NetNut. The money is small. The number of strangers using your IP address to do things you would rather not be associated with is not.

Why this one matters

  • Residential proxies are a laundering layer. They exist to make attacker traffic look like a neighbour checking their email.
  • The devices don't know. Smart TVs and streaming boxes rarely get inspected, and their owners have no visibility into what leaves them.
  • The supply chain is the app store. If a free app is quietly bundling proxy code, the consent conversation never really happens.
Google Disrupts NetNut, a 2M-Device Residential Proxy Network | RiskSense