Skip to content
Ops Enterprise 4 July 2026

Google-led operation cuts off 2 million compromised devices used as proxy cover

Diixtra | BleepingComputer

A coordinated operation involving Google has disrupted NetNut, a residential proxy network built on approximately two million compromised devices. The infected hardware was not high-end enterprise kit — it was consumer electronics: Android smart TVs, streaming boxes, and similar devices. Owners were unaware their devices were routing third-party traffic. The network was used to give attackers and other bad actors a pool of legitimate-looking IP addresses, making malicious activity harder to detect and block.

The Problem With Devices That Outlive Their Support

The infected hardware at the centre of the NetNut disruption shares a common characteristic: these are devices that receive infrequent or no security updates. A smart TV purchased in 2021 may still be in daily use while running firmware that hasn’t been patched in years. The same applies to media players, older Android set-top boxes, and a long tail of IoT devices that are online, authenticated on a home or office network, and functionally abandoned from a security maintenance perspective.

From an operational security standpoint, this is a shadow asset problem. Organisations focus their device management on laptops, desktops, and phones. The broader set of networked devices on the same physical network — conference room displays, IP cameras, smart speakers, connected printers — rarely appears on an asset inventory and almost never receives systematic patching.

What Operations Leaders Should Take From This

The NetNut disruption is a useful prompt for two practical exercises. The first is a network discovery audit: enumerate everything connected to your network, not just managed endpoints. Many organisations are surprised by what they find. The second is a segmentation review: consumer or IoT-class devices should not be on the same network segment as business systems. VLAN segmentation or a dedicated guest network for non-managed devices limits the blast radius if any of those devices are compromised.

The underlying dynamic — attackers building operational infrastructure from neglected, always-on consumer hardware — is not going away. As long as millions of devices remain connected and unpatched, they will be recruited. Disrupting one network, as significant as this operation was, does not change the supply-side economics.

Source: BleepingComputer

Want to discuss this topic?

Book a free discovery call and we'll explore how this applies to your business.