On 2 July the FBI seized the domains of NetNut. Google tore down the backend. The network - one of the largest residential proxies - was secretly turning smart TVs and routers into cover for cybercriminals and spies.
- FBI, Google, Black Lotus Labs, and Shadowserver took down NetNut - a residential proxy network of 2+ million secretly infected home devices.
- On 2 July the FBI seized hundreds of domains; Google took down the command-and-control backend.
- In just a week in June, Google detected 316 threat groups using NetNut - both cybercriminal and espionage.
The FBI, together with Google, Lumen's Black Lotus Labs, and Shadowserver (an organization that tracks cyberattacks), took down NetNut - a service selling access to over 2 million secretly infected home devices. The idea of a 'residential proxy' is simple and nasty: the attacker goes online through your TV, so the trail leads to an innocent home address - not to them.
One thing bugs me here - the silence. No TV owner ever noticed their set had been someone else's alibi for an attack. Devices at home don't have a screen that says 'espionage traffic is running through me right now.' And that's exactly why residential proxies are gold for the bad guys.
In practice: the takedown is a blow, not an ending. Google itself says the pool was cut by millions, not wiped out. The 'rent someone else's home for a few cents' model makes money and will bounce back. The real defense is more boring and more domestic: devices getting updates and not sitting on factory passwords.