Your Smart TV Was Moonlighting: Google and the FBI Unplug NetNut’s 2-Million-Device Proxy Botnet

Good news, for once, with an asterisk the size of a living room: a major residential proxy network got dismantled this week. The asterisk is that it was running on more than two million hijacked home devices, and a lot of them were the smart TV in someone’s den.

According to Google’s Threat Intelligence Group, the company — working alongside the FBI, IRS Criminal Investigation, and network intelligence firm Lumen — disrupted NetNut, a residential proxy network built atop more than two million compromised consumer devices, many of them Android smart TVs and streaming boxes. Investigators tied the network to Alarum Technologies, a Nasdaq-listed Israeli firm. In a single week in June, researchers reported observing 316 distinct threat clusters — including both cybercriminal and espionage groups — using NetNut exit nodes for password spraying and credential attacks.

What a residential proxy network is, and why attackers love them

A residential proxy routes traffic through real consumer IP addresses instead of obvious data-center ranges. For an attacker, that’s gold: malicious logins and credential-stuffing attempts blend into ordinary home-broadband traffic, making them far harder to block or even notice. Defenses that lean on flagging “suspicious” data-center IPs simply don’t fire when the connection appears to come from a residential address in the same city as the victim. The more devices in the pool, the more disposable, trustworthy-looking IPs an operator can rent out.

The devices themselves are the unwitting infrastructure. Cheap Android-based TVs and streaming boxes are a recurring problem: they ship with dated software, rarely get updates, and sometimes arrive with malware baked in before they’re ever plugged in. Once compromised, they sit quietly on home networks acting as exit nodes for other people’s crimes.

In response, the operation included several moves

  • Account disruption: Google disabled abusive accounts tied to the network.
  • Device protection: Play Protect was updated to flag the infected apps for Android users.
  • Intelligence sharing: Google shared indicators with partners to help others detect and block the activity.
  • Domain seizure: The FBI seized domains connected to the operation.

What you can do at home and at work

  • Buy boxes that get updates: Favor streaming devices and TVs from vendors with a real track record of security patches; treat suspiciously cheap no-name Android boxes as a risk.
  • Keep IoT on its own network: Segment smart TVs and streaming gear onto a separate VLAN or guest network so a compromise can’t roam.
  • Watch outbound traffic: Unexplained connections from a TV to the wider internet are worth investigating.
  • For defenders, don’t trust an IP’s reputation alone: Residential-proxy abuse means behavioral signals and MFA matter more than IP allow/deny lists.

The outrage

Let’s give credit where it’s due — a coordinated takedown spanning Google, the FBI, the IRS, and Lumen is real work, and knocking out a two-million-node proxy network is a good day. But savor it briefly, because the underlying rot is untouched. The internet is awash in cheap, unpatched, internet-connected junk that consumers buy in good faith and that turns into criminal infrastructure the moment someone reaches out and takes it.

Until there are real consequences for shipping devices with no update path — or malware pre-installed — every takedown is a game of whack-a-mole against a supply of moles that never stops growing. NetNut is down. The next residential proxy network is already recruiting from the electronics aisle. Enjoy your smart TV; just don’t let it join a botnet.

Leave a Reply

Discover more from Cyber Outrage

Subscribe now to keep reading and get access to the full archive.

Continue reading