Skip to content
Security Botnets 3 July 2026

Google-led operation cuts off 2 million devices from criminal proxy network

Diixtra | BleepingComputer

A joint operation involving Google has disrupted NetNut, a residential proxy network that gave paying subscribers access to internet traffic routed through approximately two million compromised Android devices — predominantly smart TVs and streaming boxes. The takedown cuts off those devices from the network, but the underlying problem it exposes is worth taking seriously.

What Residential Proxy Networks Do — and Why Criminals Want Them

A residential proxy network routes traffic through IP addresses belonging to real consumer devices. This makes outbound requests appear to originate from legitimate homes and businesses rather than data-centre servers, allowing operators to bypass IP-based fraud detection, geo-blocking, and automated abuse controls.

Legitimate providers operate these networks with user consent. Criminal operators build them by compromising devices without the owner’s knowledge. NetNut falls into the latter category — and its scale, two million devices, illustrates how extensively consumer IoT hardware has been recruited into criminal infrastructure.

IoT as Invisible Attack Surface

The devices forming NetNut’s network were not routers or servers. They were smart TVs, streaming boxes, and similar consumer electronics — hardware that most IT teams do not monitor and that rarely receives security updates at the same pace as managed endpoints.

This is a persistent and growing problem. Organisations routinely connect IoT and smart devices to corporate networks — building management systems, meeting room displays, connected printers, office smart TVs — often without applying the same security discipline as they would to a laptop. When those devices are compromised, their IP addresses become infrastructure for criminal activity that the organisation has no visibility into.

Practical Steps for Network Defenders

Network segmentation is the most effective control available. IoT and smart devices should sit on isolated VLANs with restricted outbound internet access and monitored egress traffic. Any device that has no legitimate reason to communicate with the internet should be blocked from doing so at the firewall.

For organisations without a formal IoT security programme, a device inventory is the right starting point: what smart and connected devices are on the network, what are they connecting to, and when were they last updated? The answers are often surprising.

The NetNut disruption is a meaningful win for defenders. The underlying vulnerability it exploited — unsecured IoT hardware with persistent network access — remains, and will be targeted again.

Read the full story on BleepingComputer

Want to discuss this topic?

Book a free discovery call and we'll explore how this applies to your business.