The scariest thing about a residential proxy network is that it can make someone else’s abuse look like your internet connection.
Google Threat Intelligence Group said on July 2 that it worked with the FBI, Lumen and other partners to disrupt NetNut, also known as Popa, a residential proxy network that Google estimates included at least 2 million devices around the world. The operation followed Google’s January 2026 disruption of IPIDEA and fits a broader push against networks that rent access to home IP addresses.
GearPulse’s view: this is relevant because the story is not only about criminals hiding traffic. It is about ordinary connected devices becoming infrastructure without the owner understanding the trade. A cheap streaming box, a sketchy app or a bandwidth-sharing promise can make a home network part of a much larger security problem.
What Google says happened
Google says the coordinated action targeted NetNut’s accounts, services, SDKs and command-and-control infrastructure. Google also says Play Protect warned users and disabled apps known to include NetNut SDKs, while technical intelligence was shared with platform providers, law enforcement and research firms.
The most important number is Google’s estimate that NetNut had at least 2 million devices in its pool. Google also says it saw 316 distinct threat clusters using suspected NetNut exit nodes during a single week in June 2026.
| Detail | Google’s public claim | Why it matters |
|---|---|---|
| Network | NetNut, also tracked as Popa | Connects a commercial proxy brand to alleged botnet infrastructure. |
| Scale | At least 2 million devices | Big enough to matter to defenders and home users. |
| Partners | FBI, Lumen and others | This was not just a private blocklist update. |
| Android defense | Play Protect warnings and app disabling | Shows mobile and TV ecosystems are part of the response. |
| Threat use | 316 clusters in one June week | Residential proxies are useful to both cybercrime and espionage groups. |
KrebsOnSecurity reported that the FBI seizure touched hundreds of domains associated with NetNut and the Popa botnet. The Register and The Hacker News both framed the disruption as part of a larger fight against proxy networks that help attackers mask their origin.
There is a caveat worth keeping in view: residential proxy services can have legitimate stated uses, and not every proxy customer is a criminal. The security issue is the enrollment model and abuse surface. If devices are compromised, preloaded with unwanted code or quietly monetized through apps, the “residential” label starts looking less like privacy tooling and more like rented victim infrastructure.
How a home device becomes a proxy node
A residential proxy network needs traffic to exit from normal home IP addresses. To get that, an operator needs code running on devices connected to normal home networks.
Google points to two broad routes. Some connected devices can arrive with unwanted software already present. Others can pick up hidden proxy code through downloaded apps, VPNs, tools or offers that pay users for spare bandwidth. Once enrolled, the device can route other people’s traffic through the home network.
| Entry point | What the user sees | What can be happening underneath |
|---|---|---|
| Cheap streaming hardware | A low-cost TV box or media stick | Preinstalled or later-added proxy code. |
| Free VPN or utility app | Privacy, speed or access claims | Third-party traffic relay or SDK behavior. |
| Bandwidth-sharing offer | Small payments for “unused internet” | Home IP rented to unknown customers. |
| Side-loaded app | Content or region unlock | Less oversight than official app stores. |
| Outdated device | No obvious change | Old software and weak update paths make abuse easier. |
The user-facing harm is not abstract. If malicious traffic leaves through your IP address, websites, services, banks or providers may flag your household as suspicious. Google also warns that outside traffic moving through a home device can expose other private devices on the same network to internet threats.
That is why this story belongs on a consumer-tech site, not just in an enterprise security feed. Smart homes are now small networks full of boxes people rarely inspect.
What to do at home
The practical advice is boring, which is a good sign.
Do not install apps that ask to monetize your bandwidth unless you fully understand the risk. Keep Google Play Protect or the equivalent platform protection enabled. Prefer official app stores. Be skeptical of no-name Android TV boxes, unusual VPNs, free streaming tools and sideloaded packages. Remove apps you do not recognize from phones, tablets, TVs and streaming boxes.
| Household check | Why it helps |
|---|---|
| Review installed apps on Android and streaming devices | Proxy SDKs often hide inside ordinary-looking apps. |
| Keep Play Protect active | Google says it warned and disabled known affected apps. |
| Avoid bandwidth-sharing apps | Payment for “unused” capacity can put your IP at risk. |
| Buy certified TV devices from reputable brands | Update paths and platform protections matter. |
| Reboot and update routers and IoT devices | Old firmware keeps forgotten devices exposed. |
| Watch for account lockouts or odd IP reputation warnings | They can signal traffic you did not initiate. |
This does not mean every cheap device is malicious or every VPN is suspect. It means the economic incentive is obvious: a real home IP address is valuable because it looks normal. If a service can quietly turn millions of homes into exit nodes, attackers will pay for that normality.
What businesses should notice
Residential proxies make abuse harder to filter because the traffic does not look like a datacenter blast. It can come from addresses attached to real ISPs, real neighborhoods and real consumer devices. That complicates fraud detection, account takeover defense, scraping controls and password-spray investigations.
For security teams, the lesson is to avoid treating “residential IP” as a trust signal by itself. Behavioral patterns, device fingerprints, login history, velocity, MFA prompts and risk scoring matter more than whether traffic exits from a normal ISP.
| Defensive habit | Why it matters against proxy abuse |
|---|---|
| Detect behavior, not just IP type | Residential exits are designed to look normal. |
| Rate-limit credential stuffing by account and pattern | IP rotation weakens simple address-based limits. |
| Treat sudden geography changes carefully | Proxy exits can move a session without moving the user. |
| Monitor scraping with content and session signals | Scrapers can rent cleaner-looking routes. |
| Share abuse intelligence quickly | Google says this ecosystem adapts and resells capacity. |
The opinion here is that takedowns help, but they are not a permanent cure. Google said proxy operators can respond by buying capacity from competitors and becoming resellers. That makes the ecosystem fluid. The defense has to assume the same abuse will reappear under different routing, branding or software.
Bottom line
Google’s NetNut disruption is relevant because it pulls a hidden infrastructure story into the living room. The device under the TV, the free app on a tablet and the promise of spare-bandwidth income can all become security decisions.
The right response is not panic. It is inventory, updates, reputable hardware, official app sources and a healthy refusal to trade your home IP address for a few dollars or a too-good-to-be-free service.
GearPulse’s read: residential proxy abuse will keep growing as long as attackers need believable traffic. The best consumer defense is to make sure your own devices are not quietly helping them look believable.