www.infosecurity-magazine.com 7/3/2026, 9:51:04 AM · external

FBI and Google disrupt NetNut botnet using hijacked devices

FBI and Google disrupt NetNut botnet using hijacked devices
Developing story breach 3 articles tracked
FBI and Google dismantle NetNut residential proxy botnet
CyberSIXT Evidence Panel Source marked as original reporting

THE FBI and Google's Threat Intelligence Group successfully disrupted the NetNut proxy network, which co-opted over two million consumer devices to facilitate cybercriminal activities. The operation targeted the network's infrastructure, seizing numerous domains. The Popa botnet, central to the network, utilized compromised Android devices to route malicious traffic through legitimate residential IP addresses.

Security experts indicated ties to Alarum Technologies Ltd, a publicly traded company, which claims its software was intended for consensual bandwidth-sharing. Following the takedown, Google implemented measures to prevent the network's reformation, causing significant operational degradation. Some confusion arose regarding the domain takedown, but experts clarified that both targeted domains were contributory to the botnet's operations.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline