Google and FBI Disrupt Massive NetNut Proxy Botnet Infecting 2 Million Devices

A coordinated operation led by Google and the FBI disrupts NetNut, a massive residential proxy network that controls at least two million infected devices worldwide. The botnet, also known as Popa, targets Android devices, smart TVs, and streaming boxes, turning them into exit nodes that route malicious traffic through legitimate home internet addresses. Cybercriminals and espionage groups rely on the network to conceal their identities while launching attacks.

Infected devices become part of the botnet through trojanized applications and pre-installed malware, including packages tied to the Badbox 2.0 operation. Once compromised, the devices route unauthorized network traffic through their residential IP addresses, often causing them to be flagged or blocked by internet service providers. Google's Threat Intelligence Group identifies NetNut as one of the largest proxy services in the world, with hundreds of threat actors using it for password-spraying attacks, infrastructure access, and targeting victim environments.

The takedown involves collaboration between Google, the FBI, Lumen Technologies, The Shadowserver Foundation, and other industry partners. The FBI seizes key domains used by the network, including netnut.com, significantly disrupting the proxy service. Google researchers observe 316 distinct threat clusters using NetNut exit nodes in a single week last month, underscoring the scale of criminal and espionage activity flowing through the network before its disruption.

Read More at the original source →