we_are_coded.by CODE · The world, decoded
БГ
FBI · Google

FBI and Google pulled the plug on 2 million hijacked home devices

Google Cloud Blog (Google Threat Intelligence Group)Security

On 2 July the FBI seized the domains of NetNut. Google tore down the backend. The network - one of the largest residential proxies - was secretly turning smart TVs and routers into cover for cybercriminals and spies.

In short
  • FBI, Google, Black Lotus Labs, and Shadowserver took down NetNut - a residential proxy network of 2+ million secretly infected home devices.
  • On 2 July the FBI seized hundreds of domains; Google took down the command-and-control backend.
  • In just a week in June, Google detected 316 threat groups using NetNut - both cybercriminal and espionage.
Checked on4 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The FBI, together with Google, Lumen's Black Lotus Labs, and Shadowserver (an organization that tracks cyberattacks), took down NetNut - a service selling access to over 2 million secretly infected home devices. The idea of a 'residential proxy' is simple and nasty: the attacker goes online through your TV, so the trail leads to an innocent home address - not to them.

The facts: on 2 July the FBI seized hundreds of NetNut domains. The network is estimated at at least 2 million compromised devices - smart TVs, routers, streaming boxes - infected through SDK-based components (ready-made third-party software) built into various products. In just one week in June, Google's team detected 316 separate threat groups using NetNut exit nodes, among them both cybercriminal and espionage actors. Google disabled the accounts and services used for command and control, and estimated the action cut 'millions' of devices from the available pool. There is no CVE: this is the takedown of a network of infected devices, not a flaw in a specific piece of software.

One thing bugs me here - the silence. No TV owner ever noticed their set had been someone else's alibi for an attack. Devices at home don't have a screen that says 'espionage traffic is running through me right now.' And that's exactly why residential proxies are gold for the bad guys.

In practice: the takedown is a blow, not an ending. Google itself says the pool was cut by millions, not wiped out. The 'rent someone else's home for a few cents' model makes money and will bounce back. The real defense is more boring and more domestic: devices getting updates and not sitting on factory passwords.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Sources
Official primary source
→Google Cloud Blog (Google Threat Intelligence Group) - "Google's Continued Disruption of Malicious Residential Proxy Networks"→Alarum Technologies (owner of NetNut) - SEC filing on the FBI domain seizure, 03.07.2026
Media confirmation
→SecurityWeek - Google, FBI Disrupt NetNut Residential Proxy Network→KrebsOnSecurity - FBI Seizes NetNut Proxy Platform, Popa Botnet
Original: https://wearecoded.com/en/articles/fbi-netnut-proxy-takedown.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news