:

GOOGLE DISRUPTS NETNUT PROXY NETWORK, CUTS 2M DEVICES

INDUSTRY DESK2 MIN READ
FRI, JUL 3, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Google has disrupted NetNut, a residential proxy network that compromised millions of Android devices, smart TVs, and streaming boxes. The joint operation effectively severed access to the infected devices.

A coordinated effort involving Google has dismantled NetNut, a residential proxy network that exploited approximately 2 million compromised devices to route traffic and mask user identities online. ■ The Network NetNut operated by leveraging infected Android devices, including smart TVs and streaming boxes, to create a proxy infrastructure. Users of the service could route internet traffic through these compromised devices to obscure their origins and bypass geographic restrictions or security measures. ■ The Operation Google's intervention successfully disrupted the network's operations, disconnecting the 2 million infected devices from the proxy infrastructure. The action prevents future use of these devices for proxy traffic routing. ■ Implications The disruption affects multiple stakeholder groups. Device owners regain control of their compromised hardware, though many may remain unaware their devices were enlisted without consent. Organizations that relied on NetNut for web scraping, ad verification, or security testing lose access to the service. Cybersecurity researchers note that residential proxy networks create significant challenges for online security and platform integrity. ■ Context Residential proxy services operate in a gray area of legality and ethics. While legitimate uses exist—including security research and ad verification—these networks frequently enable abuse including credential stuffing, price scraping, and content theft. The devices are typically compromised through malware, cracked apps, or deceptive software installation. Google's action represents a broader effort by major technology companies to combat infrastructure that enables abuse at scale. Similar operations have targeted other malicious networks and botnets in recent years. ■ Next Steps Device owners may need to take remedial action to ensure their hardware is fully cleaned of malware. Google has not announced specific user notification procedures. The operation demonstrates that even large-scale distributed networks can be disrupted through coordinated technical and legal action.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Department of Homeland Security is leveraging a little-known legal provision to request records from journalists, non-profits, and unions, according to reporting from The Guardian. The tactic raises concerns about surveillance overreach and First Amendment protections.

3H AGOIndustry Desk

Major artificial intelligence companies have issued urgent warnings that a significant cybersecurity threat could materialize within months. The alert comes as hackers continue targeting critical infrastructure across the United States.

5H AGOAI Desk

Authorities have arrested two alleged members of TeamPCP, a hacking group responsible for infecting over 1,000 organizations through supply-chain attacks.

10H AGOSecurity Desk

A Georgia police officer used Flock surveillance technology to track the movements of his ex-partner and another officer after their affair ended, according to internal investigation records.

10H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.