Google, Lumen, Shadowserver, the FBI and other partners disrupted the NetNut residential proxy network, which comprised roughly 2 million devices, mainly small streaming hardwar...
Google, Lumen, Shadowserver, the FBI and other partners disrupted the NetNut residential proxy network, which comprised roughly 2 million devices, mainly small streaming hardware, in July 2026.
Residential proxy services route traffic through ordinary home devices to hide the origin of user requests. They are legal but are frequently used by cybercriminals to conceal activity.
Researchers said the botnet was one of the most widely used residential proxy services. Google Cloud noted that the network enabled threat actors to mask IP addresses during attacks, including password spray campaigns. In a single week of June 2026, Google’s Threat Intelligence Group identified 316 distinct threat clusters using NetNut exit nodes, involving both criminal and espionage groups. The network also intersected with other botnets such as Badbox 2.0 and Mirai variants, according to public reports.
The takedown follows the January disruption of the IPIDEA proxy network. Google’s Threat Intelligence Group said that when a botnet is degraded, operators often purchase capacity from competitors, becoming resellers, which can sustain the ecosystem. The agency plans to continue monitoring the network and mapping how peers adapt. Google indicated that similar ad hoc actions may be taken in the future, but long‑term mitigation will require cooperation from ISPs, mobile platforms and other technology firms.
The residential proxy market continues to expand, and the effectiveness of targeted takedowns is limited without broader industry support.
- Publisher
- theregister
- Reliability
- high
- Published
- 7/4/2026, 10:00:21 AM
- Retrieved
- 7/4/2026, 10:00:21 AM
- Relevance
- 80%
- Confidence
- 85%

