Google and FBI Kneecap NetNut, Cutting Millions of Home Devices From Proxy Pool
Google's Threat Intelligence Group says a joint operation with the FBI and Lumen has stripped millions of infected home devices from NetNut, also tracked as Popa.

Key points
- Google's Threat Intelligence Group announced this week it had degraded the NetNut residential proxy network, also tracked as Popa.
- The operation was run jointly with the FBI and Lumen, and reduced NetNut's usable device pool by millions.
- NetNut is spread across home devices worldwide and rents that traffic capacity to third-party customers.
- Google framed the takedown as a disruption rather than a full seizure, meaning operator infrastructure remains active in some form.
Google has taken a hammer to NetNut.
The company's Threat Intelligence Group (GTIG) said this week it had gutted one of the largest residential proxy networks in operation, working alongside the FBI and Lumen. GTIG estimated the joint action stripped millions of compromised home devices out of NetNut's rentable pool.
NetNut, also tracked internally at Google as Popa, is a residential proxy operator. That's the polite term. In practice, these networks turn routers, consumer phones and other home gear into relays that route somebody else's web traffic, often traffic the paying customer would rather not run from their own IP. Ad fraud crews use them. Credential stuffers use them. So do sanctions evaders and state-linked actors hunting for a domestic-looking exit point. We first connected NetNut to its Android TV box infrastructure on 18 June, when researchers tied the Popa botnet to NetNut's parent company, NASDAQ-listed Alarum Technologies, which disputed that framing.
The economics are simple. Whoever controls the largest, cleanest pool of residential IPs wins the enterprise contracts and the criminal ones.
Google didn't disclose the specific technical mechanism it used to shrink NetNut's footprint. GTIG described the effort as a degradation rather than a full seizure, which suggests the operator's command infrastructure and business front-end remain reachable even as its inventory craters.
What should defenders patch first?
Residential proxy abuse rarely shows up as a CVE. It shows up as login attempts from IP space that looks like a Comcast subscriber in Ohio.
That's the point of the service. It defeats geo-blocks and IP reputation checks. Fraud teams at banks, retailers and ticketing platforms have been raising the alarm for years about the scale of traffic laundered through networks like NetNut and Bright Data.
Home users usually have no idea their device is enrolled. Enrollment happens through bundled SDKs in free VPN apps, cracked software and outright malware. Once installed, the device quietly answers proxy requests in the background, consuming bandwidth the owner is paying for.
NetNut's pool will rebuild. Operators of this kind rotate infrastructure, buy fresh installs from pay-per-install brokers and re-enroll devices within weeks. Blocklist-based detections will get a temporary lift, then decay.
More durable controls sit at the behavioural layer: device fingerprinting, session consistency checks and treating residential ASN traffic as suspicious when it hits sensitive endpoints like login or checkout.
GTIG and its predecessor teams disrupted the Glupteba botnet in 2021 and have kept up pressure on botnet-for-hire operators since. None of those actions killed the underlying market. They raised the cost of doing business, briefly, and pushed customers to competitors.
NetNut's operators haven't publicly responded. The FBI hasn't filed unsealed charges tied to the action as of publication. Whether this stays a technical disruption or graduates into indictments is the next thing worth watching.



