Google and FBI Shatter NetNut, Takedown 2 Million‑Device Botnet

0
29

Key Takeaways

  • Google, Lumen, Shadowserver, the FBI, and other partners disrupted the NetNut residential proxy network as part of an ongoing effort to curb tools used by cybercriminals to hide their activity.
  • NetNut operated a botnet of roughly 2 million devices, mainly low‑cost TV‑streaming hardware, and distributed its SDK under the guise of “monetizing spare bandwidth.”
  • The disruption follows a similar takedown of the IPIDEA network in January and illustrates how residential proxy providers often rely on shared infrastructure, creating downstream effects across the ecosystem.
  • Although residential proxies are not illegal, their privacy‑preserving features are frequently abused for credential‑stuffing, password‑spray attacks, espionage, and botnet propagation (e.g., Badbox 2.0, Mirai variants).
  • GTIG observed 316 distinct threat clusters using NetNut exit nodes in a single week in June 2026, underscoring the network’s appeal to malicious actors.
  • Post‑disruption, proxy operators tend to buy capacity from competitors, turning themselves into resellers and showing short‑term resilience.
  • A lasting impact will require coordinated, long‑term action involving ISPs, mobile platforms, and technology firms, rather than ad‑hoc takedowns alone.

Background of the Operation
In mid‑2026 a coalition comprising Google Cloud’s Threat Intelligence Group (GTIG), Lumen, Shadowserver, the FBI, and several other technology companies executed a coordinated degradation of the NetNut residential proxy network. The effort builds on a earlier disruption of the IPIDEA proxy network in January 2026 and signals a sustained focus on dismantling the infrastructure cybercriminals use to conceal their origin. By targeting NetNut—identified as one of the largest residential proxy providers—the alliance aimed to reduce the availability of exit nodes that malicious actors leverage for a variety of illicit activities.

Scale and Composition of NetNut’s Botnet
According to GTIG’s assessment, NetNut enrolled at least two million devices into its residential proxy fleet, with the majority being small TV‑streaming sticks and similar low‑power hardware. These devices were recruited through a software development kit (SDK) that NetNut distributed to consumers under the pretense of offering compensation for sharing unused bandwidth. Once installed, the SDK turned each device into an exit node, allowing external traffic to appear as if it originated from a legitimate residential IP address. The sheer volume of enrolled devices gave NetNut considerable reach within the proxy market.

Business Model and Monetization Tactics
NetNut marketed its SDK as a way for everyday users to earn money by letting the software run on their devices, effectively converting idle bandwidth into a revenue stream. This “monetize your spare bandwidth” pitch is common among residential proxy services and often obscures the fact that participation fuels a cybercrime ecosystem. Beyond the SDK‑based network, NetNut also sold standalone residential, mobile, and datacenter proxies, offered data‑scraping tools and curated datasets, and operated a reseller program that allowed third parties to brand and redistribute its capacity.

Interconnectedness Within the Proxy Ecosystem
Investigators noted that many other residential proxy brands appear to rely on NetNut’s underlying infrastructure, either by leasing capacity directly or by integrating NetNut‑sourced nodes into their own offerings. Consequently, the disruption of NetNut is expected to produce ripple effects across the broader residential proxy market, potentially weakening competitors that depended on its supply chain. GTIG warned that while individual networks may show short‑term resilience, the interconnected nature of the ecosystem amplifies the impact of targeting a major provider.

Observed Resilience and Adaptive Behavior
Despite the degradation, GTIG observed that proxy operators often respond to losing their own botnet by purchasing capacity from rivals, effectively becoming resellers themselves. This adaptive behavior was evident after the IPIDEA takedown, where affected providers quickly shifted to buying transit from other networks to maintain service levels. Such flexibility means that isolated disruptions may only yield temporary reductions in malicious proxy availability unless the underlying supply chains are systematically addressed.

Abuse of Residential Proxies for Cybercrime
Although residential proxy networks are not illegal per se, they are frequently abused to mask malicious traffic. Cybercriminals use these services to conceal their true IP addresses when conducting credential‑stuffing, password‑spray attacks, reconnaissance, and even espionage operations. By routing traffic through a multitude of seemingly legitimate residential IPs, attackers can evade IP‑based blacklists and reduce the likelihood of detection by security controls that rely on reputation‑based filtering.

Threat Activity Linked to NetNut
In a single week during June 2026, GTIG identified 316 distinct threat clusters that utilized NetNut exit nodes. These clusters spanned financially motivated cybercriminal groups, nation‑state‑aligned espionage actors, and other malicious entities employing the network for activities such as accessing victim environments, managing command‑and‑control infrastructure, and launching large‑scale password‑spray campaigns. The breadth of observed use underscores how integral NetNut had become to the operational toolkit of various adversaries.

Connections to Other Botnet Families
Beyond its role as a proxy provider, NetNut’s components have been spotted in the toolkits of larger botnets. GTIG reported finding plugin modules linked to the Badbox 2.0 botnet within NetNut‑associated infrastructure, while public research has also indicated that variants of the Mirai malware have leveraged NetNut nodes for propagation and distributed‑denial‑of‑service (DDoS) attacks. These linkages illustrate how residential proxy services can serve as both a camouflage layer and a distribution mechanism for broader malicious campaigns.

Domain Seizure Discrepancy
Interestingly, while the primary domain netnut.com now displays a “This website has been seized” notice, the secondary domain netnut.io remains active and unresolved. The Register’s inquiry to GTIG regarding this discrepancy did not receive an immediate response, leaving open questions about the extent of the seizure and whether residual operational capacity persists through alternate domains.

Future Outlook and Necessity for Long‑Term Strategy
Google’s announcement hinted that similar takedowns are likely to continue as the residential proxy market expands. However, GTIG emphasized that ad‑hoc disruptions, while valuable, are insufficient for lasting impact. A sustainable approach will require deeper collaboration among ISPs, mobile platform operators, and technology firms to block the recruitment of devices, monitor SDK distribution, and dismantle the financial incentives that drive users to join such networks. Only through coordinated, long‑term measures can the ecosystem be deprived of the scale and resilience that presently enable cybercriminal abuse.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here