Skip to content
IPTested
Guides / News

NetNut Takedown: What It Means for Proxy Users and How to Avoid Botnet-Sourced IPs

In July 2026, Google, the FBI and partners disrupted the NetNut proxy network, which relied on at least 2 million infected devices. What happened, why it matters if you buy residential proxies, and how to vet a provider's IP sourcing.

IPTested Editorial · ·2 min read

On July 3, 2026, Google Threat Intelligence Group (GTIG), working with the FBI, Lumen Technologies, The Shadowserver Foundation and industry partners, disrupted the NetNut residential proxy network. It's the second major residential proxy network taken down after IPIDEA.

If you use residential proxies, or plan to, this one is worth understanding.

What happened

According to BleepingComputer:

  • The FBI took down the netnut.com domain, and Google disabled accounts and services used for the malware's command-and-control infrastructure.
  • Google estimates NetNut controlled at least 2 million infected devices worldwide, including smart TVs and streaming boxes.
  • Devices were compromised through trojanized apps and botnets such as BadBox 2.0 that bundle proxy plugins. Some came pre-infected before purchase; others were infected by malicious apps users downloaded.
  • In a single week, Google observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups, for activity such as password spraying.
  • Google used Play Protect to warn users and disable infected apps.

In short: a large share of NetNut's "residential IPs" came from devices whose owners never agreed to anything.

Why it matters if you buy proxies

  1. Your service can disappear overnight. When infrastructure is seized, every workflow built on it stops, and prepaid balances may be gone.
  2. You share IPs with attackers. Heavily abused IPs end up on blocklists quickly, which drags down success rates for legitimate work.
  3. Compliance and reputation risk. If you serve business clients, routing their work through an illegitimately sourced network is a liability in itself.

How to vet a residential proxy provider

Residential IPs always come from real people's devices. What matters is whether those people knowingly opted in. Look for:

  • Transparent sourcing. Does the provider explain which apps or SDKs supply its IPs, how consent is collected, and whether users are compensated? Silence on this is a warning sign.
  • Customer KYC. Providers that vet their customers and restrict abusive use cases tend to care more about keeping their pools clean.
  • Pricing that makes sense. "Unlimited" residential bandwidth at rock-bottom prices should make you ask where the IPs come from.
  • A real, established company. Company registration, history, public terms and a privacy policy.
  • Your own testing. Check sample IPs against blocklists before you commit. Our proxy types guide includes a 5-minute pre-purchase checklist.

A note for everyday users

The affected devices included smart TVs and streaming boxes. Cheap, no-name Android boxes and apps from unofficial sources can quietly turn your home connection into someone else's proxy exit. Buy devices from reputable sellers and install apps only from official stores.

What we're doing

NetNut has been removed from our recommendations. For every residential provider we list, our review will note what the provider publicly discloses about IP sourcing, and flag it when it discloses nothing.

Browse other options in our residential proxies category.

Some links are affiliate links. We may earn a commission if you buy through them, at no extra cost to you and without affecting our ratings.