NetNut, also known as Popa, is a large malicious residential proxy botnet/network used by cybercriminal and espionage actors to conceal malicious traffic behind legitimate residential IP addresses. Reporting in the provided content estimates the network at at least 2 million compromised home devices worldwide, with some references describing losses of access to several million nodes after disruption activity. Affected devices were primarily Android-based consumer devices including smart TVs, streaming boxes, set-top boxes, and other home electronics.
The content states that NetNut enrolled devices through multiple vectors: pre-installed malicious code on low-cost or lesser-known branded devices before purchase, trojanized or free applications containing hidden proxy code or SDKs, and overlap with other malware ecosystems including Badbox 2.0; some reporting also describes Popa as a plugin/component associated with larger botnet activity. Once active, the malware turned infected devices into residential proxy exit nodes that routed third-party traffic through victims’ home internet connections. The content further notes that this exposed victims’ home IP addresses to abuse and could expose other devices on the same home network to additional threats.
According to Google Threat Intelligence Group reporting cited in the content, 316 distinct threat clusters were observed using suspected NetNut exit nodes in a single week in June 2026. Observed abuse included masking access to attacker-controlled infrastructure, password-spraying attacks, and access into victim environments. Additional cited abuse of malicious residential proxy networks included fraud, account takeovers, web scraping, and DDoS-related activity. The content also states that NetNut maintained a robust reseller and white-label ecosystem, and that many proxy brands may have been reselling the same underlying device pool.
The content links NetNut/Popa to public reporting involving Alarum Technologies, though Alarum disputed the characterization of NetNut as a botnet and described it as a legitimate consent-based proxy service. High-confidence operational details in the content include a coordinated 2026 disruption by Google, the FBI, Lumen Technologies, The Shadowserver Foundation, and other partners. Actions described included seizure of netnut.com and other domains, disabling of Google accounts and services used for command-and-control, and Google Play Protect warnings and disabling/blocking of Android applications containing NetNut SDKs. The content also references associated infrastructure and indicators including the domain netnut.com and reporting tying Popa infrastructure to ninjatech[.]io.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The real issue is the supply chain that turns consumer devices, free VPNs, Android TV boxes, torrent clients, pirated apps, and proxy SDKs into sellable residential egress.
To build that pool, operators need their code running on home devices. Some devices ship with it pre-installed on cheap off-brand hardware; others pick it up when someone installs a free app that hides it. | Google identifies NetNut, also tracked as Popa, as a network spread across home devices worldwide, including smart TVs and streaming boxes, and GTIG estimates the network holds at least 2 million devices.
Many victims unknowingly installed applications that promised payment for “unused bandwidth” or “sharing your internet,” a common lure for these networks.
They need residential egress that still works: clean-looking IPs, geographic routing, rotation, uptime, and enough abstraction to keep credential stuffing, scraping, fake account creation, ad fraud, account takeover, and other abuse moving.
When traffic arrives from DiviNetworks through the GRE tunnel, RouterOS records that connection using a connection mark named DIVINET-RETURN. Subsequent packets associated with those marked connections are assigned a routing mark that causes route lookups to occur in the DIVINET-TUNNEL routing table.
Attackers are not buying malware for its own sake. They are buying the ability to make abusive traffic look local, distributed, and harder to score.
When traffic arrives from DiviNetworks through the GRE tunnel, RouterOS records that connection using a connection mark named DIVINET-RETURN. Subsequent packets associated with those marked connections are assigned a routing mark that causes route lookups to occur in the DIVINET-TUNNEL routing table.
Google observed 316 distinct threat clusters using suspected NetNut exit nodes to mask their location and carry out activities such as password guessing and malware distribution.
Google said it disabled Google accounts and services used for malware command-and-control, shared technical intelligence on NetNut SDKs and backend C2 infrastructure...
Anyone with a NetNut account (or with access through numerous resellers) can route traffic out of that address space.
NetNut's ISP proxy product is implemented through GRE tunnels and policy routing on partner networks, converting publicly registered IP space into a commercial anonymity commodity.
When traffic arrives from DiviNetworks through the GRE tunnel, RouterOS records that connection using a connection mark named DIVINET-RETURN. Subsequent packets associated with those marked connections are assigned a routing mark that causes route lookups to occur in the DIVINET-TUNNEL routing table.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Residential proxy botnet built from compromised devices, mainly Android smart TVs and streaming boxes, used to route unauthorized traffic through legitimate residential IP addresses and mask malicious activity.
A malicious residential proxy network/botnet built from compromised consumer home devices such as smart TVs and streaming boxes. It routes traffic through infected devices so cybercriminals can conceal origin IPs and support activities including fraud, account takeovers, password spraying, web scraping, and DDoS-related abuse.
A massive residential proxy botnet made up of compromised Android devices, rented out to cybercriminal and espionage actors to mask their identities during attacks. Google and the FBI disrupted its backend infrastructure and reduced its device pool by millions.
A malicious residential proxy network/botnet that compromises home devices and routes proxy traffic through them. Google says it used Google accounts and services for malware command-and-control, and researchers linked its SDKs and backend infrastructure to a large-scale proxy resale ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.