Google's NetNut takedown makes home devices part of the security story

Google says it worked with the FBI, Lumen and other partners to disrupt the NetNut residential proxy network, which it estimates touched at least 2 million devices. The audience lesson is practical: cheap connected devices, free VPN-style apps and bandwidth-sharing offers can quietly turn a home network into someone else's infrastructure.

Official Google Cloud Threat Intelligence graphic used for residential proxy network disruption coverage.
Official image from Google Cloud.

The scariest thing about a residential proxy network is that it can make someone else’s abuse look like your internet connection.

Google Threat Intelligence Group said on July 2 that it worked with the FBI, Lumen and other partners to disrupt NetNut, also known as Popa, a residential proxy network that Google estimates included at least 2 million devices around the world. The operation followed Google’s January 2026 disruption of IPIDEA and fits a broader push against networks that rent access to home IP addresses.

GearPulse’s view: this is relevant because the story is not only about criminals hiding traffic. It is about ordinary connected devices becoming infrastructure without the owner understanding the trade. A cheap streaming box, a sketchy app or a bandwidth-sharing promise can make a home network part of a much larger security problem.

What Google says happened

Google says the coordinated action targeted NetNut’s accounts, services, SDKs and command-and-control infrastructure. Google also says Play Protect warned users and disabled apps known to include NetNut SDKs, while technical intelligence was shared with platform providers, law enforcement and research firms.

The most important number is Google’s estimate that NetNut had at least 2 million devices in its pool. Google also says it saw 316 distinct threat clusters using suspected NetNut exit nodes during a single week in June 2026.

DetailGoogle’s public claimWhy it matters
NetworkNetNut, also tracked as PopaConnects a commercial proxy brand to alleged botnet infrastructure.
ScaleAt least 2 million devicesBig enough to matter to defenders and home users.
PartnersFBI, Lumen and othersThis was not just a private blocklist update.
Android defensePlay Protect warnings and app disablingShows mobile and TV ecosystems are part of the response.
Threat use316 clusters in one June weekResidential proxies are useful to both cybercrime and espionage groups.

KrebsOnSecurity reported that the FBI seizure touched hundreds of domains associated with NetNut and the Popa botnet. The Register and The Hacker News both framed the disruption as part of a larger fight against proxy networks that help attackers mask their origin.

There is a caveat worth keeping in view: residential proxy services can have legitimate stated uses, and not every proxy customer is a criminal. The security issue is the enrollment model and abuse surface. If devices are compromised, preloaded with unwanted code or quietly monetized through apps, the “residential” label starts looking less like privacy tooling and more like rented victim infrastructure.

How a home device becomes a proxy node

A residential proxy network needs traffic to exit from normal home IP addresses. To get that, an operator needs code running on devices connected to normal home networks.

Google points to two broad routes. Some connected devices can arrive with unwanted software already present. Others can pick up hidden proxy code through downloaded apps, VPNs, tools or offers that pay users for spare bandwidth. Once enrolled, the device can route other people’s traffic through the home network.

Entry pointWhat the user seesWhat can be happening underneath
Cheap streaming hardwareA low-cost TV box or media stickPreinstalled or later-added proxy code.
Free VPN or utility appPrivacy, speed or access claimsThird-party traffic relay or SDK behavior.
Bandwidth-sharing offerSmall payments for “unused internet”Home IP rented to unknown customers.
Side-loaded appContent or region unlockLess oversight than official app stores.
Outdated deviceNo obvious changeOld software and weak update paths make abuse easier.

The user-facing harm is not abstract. If malicious traffic leaves through your IP address, websites, services, banks or providers may flag your household as suspicious. Google also warns that outside traffic moving through a home device can expose other private devices on the same network to internet threats.

That is why this story belongs on a consumer-tech site, not just in an enterprise security feed. Smart homes are now small networks full of boxes people rarely inspect.

What to do at home

The practical advice is boring, which is a good sign.

Do not install apps that ask to monetize your bandwidth unless you fully understand the risk. Keep Google Play Protect or the equivalent platform protection enabled. Prefer official app stores. Be skeptical of no-name Android TV boxes, unusual VPNs, free streaming tools and sideloaded packages. Remove apps you do not recognize from phones, tablets, TVs and streaming boxes.

Household checkWhy it helps
Review installed apps on Android and streaming devicesProxy SDKs often hide inside ordinary-looking apps.
Keep Play Protect activeGoogle says it warned and disabled known affected apps.
Avoid bandwidth-sharing appsPayment for “unused” capacity can put your IP at risk.
Buy certified TV devices from reputable brandsUpdate paths and platform protections matter.
Reboot and update routers and IoT devicesOld firmware keeps forgotten devices exposed.
Watch for account lockouts or odd IP reputation warningsThey can signal traffic you did not initiate.

This does not mean every cheap device is malicious or every VPN is suspect. It means the economic incentive is obvious: a real home IP address is valuable because it looks normal. If a service can quietly turn millions of homes into exit nodes, attackers will pay for that normality.

What businesses should notice

Residential proxies make abuse harder to filter because the traffic does not look like a datacenter blast. It can come from addresses attached to real ISPs, real neighborhoods and real consumer devices. That complicates fraud detection, account takeover defense, scraping controls and password-spray investigations.

For security teams, the lesson is to avoid treating “residential IP” as a trust signal by itself. Behavioral patterns, device fingerprints, login history, velocity, MFA prompts and risk scoring matter more than whether traffic exits from a normal ISP.

Defensive habitWhy it matters against proxy abuse
Detect behavior, not just IP typeResidential exits are designed to look normal.
Rate-limit credential stuffing by account and patternIP rotation weakens simple address-based limits.
Treat sudden geography changes carefullyProxy exits can move a session without moving the user.
Monitor scraping with content and session signalsScrapers can rent cleaner-looking routes.
Share abuse intelligence quicklyGoogle says this ecosystem adapts and resells capacity.

The opinion here is that takedowns help, but they are not a permanent cure. Google said proxy operators can respond by buying capacity from competitors and becoming resellers. That makes the ecosystem fluid. The defense has to assume the same abuse will reappear under different routing, branding or software.

Bottom line

Google’s NetNut disruption is relevant because it pulls a hidden infrastructure story into the living room. The device under the TV, the free app on a tablet and the promise of spare-bandwidth income can all become security decisions.

The right response is not panic. It is inventory, updates, reputable hardware, official app sources and a healthy refusal to trade your home IP address for a few dollars or a too-good-to-be-free service.

GearPulse’s read: residential proxy abuse will keep growing as long as attackers need believable traffic. The best consumer defense is to make sure your own devices are not quietly helping them look believable.