On July 2, 2026, Google, the FBI, and a coalition of international partners carried out a coordinated operation against NetNut, a residential proxy network operated by Alarum Technologies. The action protected more than 2 million compromised devices worldwide, dismantling what had become a critical piece of infrastructure for cybercriminals and state-sponsored espionage groups alike.
What Was NetNut and Why Did It Matter
A Hidden Network Inside Consumer Devices
NetNut operated as a residential proxy network — in practice, it hijacked millions of consumer devices, including routers and smartphones, turning them into unwitting exit nodes for malicious traffic.
This type of infrastructure is particularly insidious. Traffic routed through residential IP addresses appears legitimate to conventional security tools, making criminal activity far harder to trace or block.
The Link to the Popa Botnet
Alongside the NetNut takedown, authorities also dismantled the Popa botnet. According to Google Threat Intelligence, the two infrastructures were closely intertwined: the Popa botnet was used to recruit and maintain the pool of compromised devices feeding into the network.
Alarum Technologies marketed access to these devices as a legitimate commercial service — but the underlying infrastructure was being actively exploited by malicious actors for unlawful operations at scale.
The Operation: Google, FBI, and Partners Move In
An Unprecedented Coalition
The operation brought together Google, the FBI, Lumen, and other private-sector partners — a model that is rapidly becoming the standard for responding to large-scale cyber threats. Law enforcement and tech companies acted in lockstep.
The FBI seized hundreds of domains tied to the infrastructure, while associated accounts and services were disabled, severing the network’s command-and-control chain.
What Was Actually Achieved
Google reported reducing the pool of available devices within NetNut by millions of units, with over 2 million compromised devices effectively protected. It stands as one of the most significant takedowns of a residential proxy network to date.
Critically, the operation went beyond technical disruption. It encompassed legal action, notifications to affected users, and a coordinated public awareness campaign — underscoring the effectiveness of tight coordination between the private sector and government authorities.
Why Residential Proxy Networks Are a Threat to Enterprises
The Risk for CISOs and Security Leaders
Residential proxy networks like NetNut pose a specific challenge for enterprise security teams. Malicious traffic originating from residential IP addresses bypasses many filtering systems — it simply looks like normal user activity.
These services are routinely leveraged for:
- Credential stuffing: automated attacks designed to compromise accounts using stolen credentials
- Ad fraud: generating fake traffic to monetize digital advertising campaigns
- State-sponsored espionage: APT groups use them to mask reconnaissance operations
- Sanctions evasion: circumventing geographic restrictions on platforms and services
The disruption of NetNut has therefore had a direct and measurable impact on reducing these activities at a global level.
Implications for Enterprise Defense
That said, this operation does not eliminate the problem at its root. Similar networks will continue to emerge, and organizations need to adopt proactive measures.
CISOs should consider the following steps:
- Monitor for anomalous traffic patterns, including those originating from residential IP ranges
- Keep all network-connected devices updated, including routers and IoT endpoints
- Leverage up-to-date threat intelligence to identify IP addresses known to function as proxies
- Partner with intelligence platforms like IsacChain to receive timely, actionable alerts
Conclusion: A Strong Signal to the Cybercrime Ecosystem
The operation against NetNut sends a clear message: public-private coalitions can take down even large-scale criminal infrastructures. The collaboration between Google, the FBI, and Lumen has demonstrated that no network is untouchable.
The case also highlights how the line between commercial services and criminal infrastructure is growing dangerously thin. Companies offering access to residential proxy pools are now under much sharper scrutiny — and the bar for accountability is rising.
For IsacChain and the Italian threat intelligence community, this case sets an important benchmark. It validates the fundamental value of information sharing between the public and private sectors as a force multiplier against organized cybercrime.
Sources:
- Reuters – Google disrupts NetNut proxy network
- Google Cloud Blog – Continued Disruption of Residential Proxy Networks
- Infosecurity Magazine – FBI and Google Take Down NetNut Proxy
- KrebsOnSecurity – FBI Seizes NetNut Proxy Platform / Popa Botnet
Source: Original article
The NetNut case makes one thing abundantly clear: timely threat intelligence sharing between public and private organizations is no longer optional — it is essential. Platforms like IsacChain enable Italian and European companies to exchange indicators of compromise in a secure, blockchain-verified environment, dramatically cutting response times to threats such as residential proxy networks. The platform’s built-in automated NIS2 compliance layer also allows security teams to document every defensive action without added operational burden. Discover how IsacChain can help your organization at www.isacchain.com