HomeSecurityNetNut / Popa: Google disrupts residential proxy network

NetNut / Popa: Google disrupts residential proxy network

Google has announced a major cybersecurity success , announcing that it has taken down NetNut , one of the world’s largest residential proxy networks. The operation, carried out in collaboration with the FBI, Lumen and other security organizations , resulted in the removal of millions of home devices from the network’s infrastructure.

Article Image: Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices

According to the Google Threat Intelligence Group (GTIG), NetNut – also known as Popa – was exploiting more than two million connected devices worldwide, including Android TV boxes, streaming players, and smart TVs, which were used as intermediate nodes to transport third-party web traffic.

What are residential proxy networks?

Residential proxy networks are a special class of services that offer access to real home internet connections. Unlike servers hosted in data centers, home IPs are considered more reliable by many internet services, as they resemble the normal activity of an ordinary user.

See also: IPIDEA: Google “hit” one of the largest Residential Proxy Networks

This feature makes them particularly attractive to cybercriminals. Through them, they can hide their true location, bypass website protection mechanisms , and carry out attacks without the origin of their traffic being easily revealed.

In practice, if a home device is joined to such a network, unknown users can channel their own online activity through its owner's connection, creating significant risks to both security and reputation.

How devices become "exit nodes"

There are more than one way to join a device in such a network. In many cases, proxy software is already pre-installed on inexpensive devices of unknown origin. In other cases, it is installed through free applications that hide this functionality from the user.

Once activated, the device acts as an “exit node,” allowing third-party data to pass through your home connection. Google warns that this process is not limited to just transferring traffic, but can create an additional access point to other devices on the same local network.

The situation becomes even more dangerous when such devices are integrated into botnets like Mirai and Badbox 2.0, which are often used for large-scale attacks.

NetNut / Popa: Google disrupts residential proxy network

Use by criminal organizations and espionage groups

GTIG data reveals the scale of the problem. In just one week in June, 316 different threat groups were identified that were leveraging NetNut nodes to hide their true origins.

These included cybercrime groups, as well as entities linked to digital espionage. The infrastructure was used for brute force attacks on user accounts, as well as other malicious actions requiring a wide spread of IP addresses.

The connection with Alarum Technologies

Of particular interest is the fact that NetNut is associated with Israeli-based Alarum Technologies, a publicly traded company. Researchers from Qurium, Synthient, Nokia Deepfield, and Spur have argued that Popa and NetNut are essentially the same infrastructure.

See also: Google Home Speaker: Great speaker, but Gemini isn't ready

Google itself says its own findings are consistent with this assessment. Alarum, on the other hand, categorically rejects the “botnet” designation, claiming that its service is based solely on voluntary bandwidth sharing and that it does not put devices at risk .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

However, tests by independent researchers showed that many applications participating in the network did not clearly inform users that their connection would be used to carry third-party traffic, which raises serious questions about consent.

Why dislocation does not permanently solve the problem

Despite the company's significant success, Google makes it clear that this is a "downgrade" and not a complete shutdown of the network. NetNut has an extensive reseller program, allowing many different proxy services to leverage the same infrastructure under different brand names.

This means that even if a provider stops operating, the same infrastructure can reappear through other partners or competing services. A similar picture was recorded in the operations against IPIDEA and Badbox 2.0, which returned in different forms after the initial interventions of the authorities.

See also: Google Home finally has a plan to fix Nest Cam's 'Familiar Faces'

NetNut / Popa: Google disrupts residential proxy network

How can users be protected?

Experts advise consumers to avoid apps that promise financial rewards for “utilizing unused bandwidth” or sharing their internet connection. They also recommend installing apps only from official app stores, keeping enabled Google Play Protect , and purchasing smart TVs or streaming devices only from trusted manufacturers.

Google's recent operation is a significant blow to NetNut, but the demand for residential proxies remains extremely high. This means that criminal organizations will continue to seek new infrastructure, making the vigilance of users, companies, and cybersecurity researchers more necessary than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS