Cybersecurity

Your Smart TV’s Secret Life: How Google and the FBI Toppled a Proxy Empire

A massive joint operation has dismantled NetNut, a 2-million device botnet that turned home streaming boxes into tools for international cybercrime.

Jordan Blake 5 min read
Your Smart TV’s Secret Life: How Google and the FBI Toppled a Proxy Empire

Key takeaways

  • The NetNut botnet (Popa) leveraged 2 million Android-based smart TVs and streaming boxes to fuel cyberattacks.
  • The network was owned by Alarum Technologies, a Nasdaq-listed company, highlighting a troubling link between commercial services and malware.
  • Google and the FBI seized domains and dismantled infrastructure to stop over 300 threat clusters from using the hijacked IPs.
  • Users are advised to rely on Google Play Protect and official firmware updates to secure their IoT devices from similar proxy SDKs.

The Double Life of Your Living Room Electronics

That shiny new smart TV in your living room might have been leading a secret double life as a high-priced getaway car for international cybercriminals. On July 2, 2026, a massive coordinated strike by Google and the FBI successfully disrupted the NetNut residential proxy network, also known as the Popa botnet. According to a report by Bleeping Computer, this operation cut off a sprawling infrastructure that leveraged at least 2 million compromised Android devices, primarily smart TVs and streaming boxes, to conceal malicious traffic for over 300 threat clusters in a single week.

This was not your typical underground botnet run by a lone hacker in a basement. NetNut operated as a commercial proxy service owned by Alarum Technologies, an Israeli firm listed on the Nasdaq. The company reportedly rented these hijacked IP addresses to various cybercriminals and espionage groups, even offering a reseller program that allowed other brands to whitelabel the botnet for their own customers. The disruption marks a turning point in how law enforcement and tech giants view the intersection of legitimate business and malicious infrastructure.

What Changed: From Underground to Wall Street

Traditionally, botnets are seen as purely criminal enterprises, hidden in the dark corners of the web. What is new here is the scale of corporate involvement and the normalization of proxy services built on stolen resources. As Google’s Threat Intelligence Group detailed in a recent technical breakdown, the operation exposed a critical flaw in the commercial proxy industry: legitimate services can and do intersect with malware networks like Badbox 2.0 and the Kimwolf DDoS botnet. These groups used trojanized applications to infect home devices, effectively packaging proxy plugins into everyday apps that users trusted.

By July 4, 2026, the digital landscape looked significantly different. The FBI and IRS Criminal Investigation seized key domains including netnut.com, proxyjet.io, and divinetworks.com, replacing their homepages with federal seizure notices. Google took further action by disabling command and control accounts and updating Google Play Protect to automatically warn users and disable infected apps containing the NetNut SDK.

Why It Matters: The Risk in Your Router

For the average consumer, this news is a wake up call about the vulnerability of the Internet of Things. While your device might not feel slow, having your home IP address used as a relay for malicious actors exposes you to significant risks. Security experts highlight that the 316 distinct threat clusters using NetNut for password spray attacks were essentially using your home identity to bypass security filters at major banks and retailers. According to researchers at HackRead, the use of residential IPs makes these attacks nearly impossible to distinguish from legitimate traffic, putting the owner of the IP at risk of being blacklisted or even targeted for investigation.

Furthermore, the incident raises deep questions about corporate oversight. As Alarum Technologies is a publicly traded company, the Reuters report on the disruption emphasizes the growing concern over the legality of profiting from infrastructure linked to botnets. The FBI’s year long examination suggests that the ties between the commercial service and the malware operations were far from accidental.

Context: What is a Residential Proxy?

For those new to the term, a residential proxy is a service that routes internet traffic through a real home device rather than a data center. While there are legitimate uses, such as market research or price comparison, they are highly sought after by cybercriminals. By appearing to be a regular home user, attackers can bypass geographic restrictions and security systems that would otherwise block traffic coming from known server farms.

What to Watch Next

This disruption follows Google’s January 2026 dismantling of the IPIDEA proxy network, suggesting a coordinated, long-term effort to dismantle the entire ecosystem of malicious residential proxy providers. We should expect to see increased scrutiny of proxy companies listed on public stock exchanges and perhaps new regulations regarding how these firms verify the source of their IP addresses. Additionally, the software supply chain will remain a primary battleground. As seen in the North Korean PolinRider campaign, attackers are increasingly moving away from direct hacking and toward poisoning the apps and packages that we all rely on.

To protect yourself, ensure your smart TVs and streaming boxes are running the latest firmware and avoid sideloading apps from third-party sources. The era of the invisible botnet is far from over, but the walls are closing in on those who profit from our hijacked hardware.

Discussion (0)

Join the discussion

Delete comment?

This action cannot be undone.

Jordan Blake

Mobile ecosystem analyst and smartphone reviewer