Back to Blog
Insights

Residential Proxy Botnet: How NetNut Powers Attacks

Residential Proxy Botnet: How NetNut Powers Attacks

In early July 2026, Google's Threat Intelligence Group (GTIG), the FBI, IRS Criminal Investigation, Lumen and the Shadowserver Foundation disrupted NetNut, a residential proxy network that GTIG estimates ran on at least two million devices worldwide, tracked as the Popa botnet. The FBI seized hundreds of domains tied to the network, replaced NetNut's homepage with a seizure banner and moved its nameservers to ns1.fbi.seized.gov.

If your business runs a login page, a checkout, or any internet-facing app, this story matters to you, even though not one of those two million devices is yours. NetNut is the plumbing behind much of the credential stuffing, password spraying, account takeover, and scraping that hammers business applications every day. Take down the plumbing and you disrupt the attacks. Here is how it worked, the uncomfortable question at the centre of it, and what defenders should take away.

How NetNut hijacked 2 million home devices, what attackers rent it for, and how to defend, an IKZERO threat brief

What a residential proxy botnet actually is

A residential proxy routes an attacker's traffic through a real home's internet connection, so it arrives at your servers looking like an ordinary customer on a residential ISP, not a datacentre, not a known-bad IP. That is the entire value proposition: it defeats IP-based defence.

Blocklists, geo-fencing, "impossible travel" rules, and rate limits all lean heavily on the assumption that malicious traffic comes from suspicious infrastructure. Residential proxies erase that assumption. When an attacker sprays thousands of passwords across your logins from thousands of different real home IPs, each request looks like a different legitimate user. That is why these networks are the preferred infrastructure for exactly the attacks that reach your front door.

How NetNut built a two-million-device botnet

NetNut did not hack its way onto those devices one by one. It industrialised enrolment through the software supply chain of cheap consumer electronics:

GTIG also identified NetNut botnet plugin components for large-scale botnets such as Badbox 2.0, and points to public reporting by Synthient, Spur and Nokia Deepfield documenting NetNut being used to infect devices with Mirai DDoS variants. One compromised device often serves multiple criminal purposes at once.

Who used it, and for what

This is not a fringe tool. In a single week during June 2026, GTIG observed 316 distinct threat clusters (both cybercriminal and espionage groups) using suspected NetNut exit nodes. Their activity reads like a catalogue of the attacks a security operations centre triages daily:

There is also a nasty local twist. GTIG puts it plainly: when a consumer device becomes an exit node, unauthorised network traffic passes through it, which means bad actors can reach other private devices on the same home network. The botnet doesn't just borrow the IP; it plants a foothold inside the home.

The uncomfortable part: this was a public company

Here is what makes NetNut different from a typical botnet. Per Krebs on Security, NetNut was operated by Alarum Technologies (NASDAQ: ALAR), a publicly-traded Israeli company, and its proxy access was widely resold and white-labeled by third-party providers. Google observed customers using it primarily for scraping, ad fraud, and account takeover.

To be fair to the company: this was a seizure and a disruption, not a verdict. Alarum said publicly that it takes the matter seriously and would fully cooperate with law enforcement so any misuse of its infrastructure is investigated, and no criminal charges against the company have been announced at the time of writing.

Still, it blurs a line the whole industry would prefer stayed sharp. A "residential proxy service" and a "botnet" can be the same two million hijacked devices, sold with a slick dashboard and an invoice. For defenders, the takeaway is blunt: the infrastructure attacking you is a commercial product, cheap, abundant, and (until a takedown like this) entirely legal-looking.

How the takedown worked

The disruption was coordinated across the ecosystem rather than a single raid:

Google said the coordinated actions caused "significant degradation" to NetNut's network and business, "reducing the available pool of devices for the proxy operator by millions". It builds on GTIG's January 2026 disruption of the IPIDEA proxy network, a sign this is now a sustained campaign against the residential-proxy industry, not a one-off.

Why this matters to defenders

You cannot patch your way out of NetNut, and you cannot simply block it. That is the point. Two lessons stand out:

  • IP reputation is no longer a control on its own. If your bot defence, WAF, or fraud engine relies on blocking "bad" IPs, residential proxies walk straight through it. Detection has to move to behaviour (velocity, sequencing, device and session fingerprinting, and impossible-behaviour analysis), not origin.
  • Cheap IoT is an untrusted supply chain. Budget smart TVs, streaming boxes, and "free bandwidth" apps are shipping as attack infrastructure. Anything like that on a corporate or executive network is a liability, not a convenience.

How to defend your business

  • Kill password-based attacks at the source. Password spraying and credential stuffing only work because passwords do. Enforce phishing-resistant MFA or passkeys, and monitor for spray patterns (many accounts, one password; low-and-slow attempts across many IPs). Validating that these defences actually hold is core penetration testing work.
  • Detect behaviour, not just IPs. Residential-proxy traffic evades reputation blocking, so lean on anomaly detection at the login and application layer: session velocity, geolocation churn within a session, and automation fingerprints. This is exactly what a 24/7 managed detection and response capability is built to catch.
  • Add real bot management. Deploy defences that score requests on behaviour and device signals rather than IP alone, and rate-limit sensitive endpoints (login, password reset, checkout, API) per-account, not just per-IP.
  • Test yourself the way attackers hit you. Have your authentication and fraud controls exercised against residential-proxy-style, distributed attacks: a red team or targeted assessment shows whether your defences survive traffic that looks legitimate.
  • Segment and monitor IoT. Keep smart TVs, streaming devices, and other consumer IoT off networks that touch anything sensitive, restrict their egress, and buy connected hardware only from reputable manufacturers.

NetNut is disrupted, but the residential-proxy market is much bigger than one provider, and a competitor will fill the gap. The durable defence is not blocking one network. It is building controls that assume the attacker looks exactly like your customers. If you want to know whether yours do, talk to our team.

Frequently Asked Questions

What is NetNut?

NetNut is a residential proxy network (tracked as the Popa botnet) that routed customers' internet traffic through home devices such as smart TVs and streaming boxes. Google's Threat Intelligence Group estimates its size at two million devices or more. In early July 2026 it was disrupted by GTIG, the FBI, IRS Criminal Investigation, and partners including Lumen and the Shadowserver Foundation.

What is a residential proxy botnet, and why is it dangerous?

It is a network of compromised home devices used to relay other people's internet traffic, making that traffic appear to come from ordinary residential users. It is dangerous because it defeats IP-based defences: attackers can run password spraying, credential stuffing, account takeover, and scraping while blending in with legitimate customers on residential ISPs.

How did devices get infected?

Through the consumer-electronics supply chain: proxy code pre-installed on budget streaming boxes, hidden SDKs inside smart-TV apps, apps that pay users for "unused bandwidth," and add-ons needed to stream pirated content. Residential proxy SDKs are widespread on TV app stores generally: Spur's June 2026 scan of 6,038 LG and Samsung apps found more than 42% of LG webOS apps and more than a quarter of Samsung Tizen apps carrying such code, mostly from commercial proxy vendors rather than NetNut. NetNut components were also tied to the Badbox 2.0 and Mirai botnets.

Was NetNut actually illegal? It sounds like a business.

That is the uncomfortable part. NetNut was operated by Alarum Technologies, a publicly-traded company, and its access was resold and white-labeled widely. What made researchers call it a botnet is the infrastructure: Krebs on Security describes Popa as at least two million devices compromised with little or no consent from victims. That said, this was a law-enforcement seizure, not a court ruling. No criminal charges against Alarum have been announced at the time of writing, and the company said it would fully cooperate with law enforcement.

How do we defend our business against attacks from residential proxies?

Stop relying on IP reputation alone. Enforce phishing-resistant MFA or passkeys, detect behaviour rather than origin (session velocity, automation fingerprints, per-account rate limits), deploy real bot management, segment consumer IoT away from sensitive networks, and test your authentication and fraud controls against distributed, legitimate-looking traffic.

Sources

Get Started

Want a security-first build?

Get a free security review. We'll look at where you stand today and tell you what to fix first, no strings attached.

Talk to an Expert
Residential Proxy Botnet: How NetNut Powers Attacks - IKZERO