Millions of smart home devices sit quietly in living rooms worldwide, but some may have been transformed into hidden internet gateways without their owners knowing. Google says a residential proxy network allegedly used at least 2 million consumer devices as traffic relays for cybercriminal activity.
The NetNut case highlights a growing security concern for smart home owners. Cheap Android TV boxes, streaming devices, and apps that promise rewards for sharing internet connections can pose unexpected risks by giving criminals access to residential networks.
How did consumer devices become part of a proxy network?
Google described NetNut as a residential proxy provider whose network allegedly relied on compromised consumer hardware. Residential proxies are normally marketed as tools that allow businesses to route traffic through real household IP addresses for testing, research, or other legitimate purposes.
However, Google said the network was abused to hide malicious activity by making internet traffic appear to originate from ordinary home connections. This approach makes cyberattacks harder to detect because residential IP addresses often receive more trust than known data center proxies.
The company said the suspected network included at least 2 million devices distributed worldwide. Google also identified 316 distinct threat clusters that used suspected NetNut proxy exit nodes, including groups linked to cybercrime and espionage.
Why are residential proxies attractive to attackers?
A residential proxy works by routing online requests through internet connections assigned to homes rather than commercial servers. This can help companies perform legitimate tasks, such as checking regional search results or managing online services across different locations.
The same technology can become dangerous when criminals use it to conceal their origins. Google said attackers used suspected NetNut exit nodes to mask their IP addresses while accessing victim environments and conducting password spray attacks.
Password spraying involves trying common passwords across multiple accounts rather than repeatedly attacking a single account. By spreading activity across thousands of residential addresses, attackers can avoid some traditional security filters that identify unusual traffic patterns.
How did the alleged operation spread?
Google said the network grew through software development kits distributed inside applications and devices commonly found in homes. These kits allegedly provided persistent access, allowing devices to relay internet traffic without the owners’ knowledge.
The affected products reportedly included Android TV boxes and streaming hardware, especially lower-cost devices from less established manufacturers. Many consumers purchase these products because they offer cheaper access to streaming features than major brands.
Once compromised, devices could function as exit nodes. That means that outside traffic passed through a household’s internet connection, making activity appear to originate from that home rather than a suspicious external source.
Little-known fact: NetNut’s proxy code has reportedly been found bundled inside the Badbox 2.0 botnet, a separate operation that hijacked over a million off-brand Android devices.
Why should smart homeowners pay attention?
Smart home security is increasingly connected to the trustworthiness of everyday devices. A streaming box may seem harmless, but poorly secured hardware can become a weak point inside a home network.
Google warned that when a consumer device becomes an unauthorized exit node, attackers may gain the opportunity to reach other devices on the same network. This could expose computers, phones, cameras, and other smart home products to additional risks.
The company specifically advised consumers to be cautious about apps offering payments for “unused bandwidth” or “sharing your internet.” These programs can provide a simple way for malicious proxy networks to expand their reach.
What activities were linked to the network?
Google said suspected NetNut proxy nodes were used by cybercriminal and espionage groups seeking anonymity. By routing activity through household connections, attackers could make malicious operations appear more like normal consumer internet usage.
The suspected abuse included password spraying, unauthorized access attempts, and other activities designed to compromise accounts or networks. Residential proxy access can be valuable because many security systems treat home IP addresses differently from known malicious infrastructure.
Google also identified ad fraud as another possible use of hijacked traffic. Criminal groups can generate fake visits, manipulate online engagement metrics, and generate revenue streams by leveraging large numbers of compromised devices.
How did Google respond to the alleged threat?
Google said it worked with the Federal Bureau of Investigation and Lumen Technologies to disrupt the network. The company disabled Google accounts and services that were allegedly used for controlling parts of the operation.
Google also expanded protections through Google Play Protect, which helps Android users detect harmful applications. The company said Play Protect was disabling applications containing NetNut software development kits and would continue blocking future installation attempts.
The disruption reportedly reduced the proxy operator’s available device pool by millions. However, Google warned that operators behind these networks may attempt to rebuild by purchasing proxy capacity from other sources.
Little-known fact: After Google disrupted the rival IPIDEA proxy network in January 2026, research firm Bitsight found its device count had rebuilt to pre-takedown levels within a single day.

What does this mean for device buyers?
The NetNut case shows how inexpensive smart home products can create security concerns beyond traditional malware infections. A device does not need to steal files or display warnings to cause harm if it quietly becomes part of a larger network.
Consumers should consider buying streaming devices from reputable manufacturers that provide regular security updates. Unknown brands offering unusually cheap hardware may carry greater risks, especially when their software supply chains are unclear.
Security researchers have increasingly focused on how consumer devices are turned into infrastructure for proxy networks, botnets, and other services. The problem extends beyond a single company because the business model can be replicated with new devices and applications.
Is this part of a larger proxy network problem?
The NetNut disruption follows a broader trend involving residential proxy networks that use compromised devices to provide anonymous internet access. Google has previously worked on similar disruptions involving other proxy ecosystems.
The model is attractive to criminals because it combines scale with anonymity. By compromising affordable devices and hiding traffic inside normal residential networks, operators can offer access that is harder for security systems to identify and block.
Google said the company’s actions were designed to disrupt malicious residential proxy operations rather than target legitimate uses of proxy technology. The challenge is separating lawful services from networks built on unauthorized access.
Little-known fact: NetNut runs a reseller program letting other brands sell its network under their own names, and Google has high confidence that many “independent” proxy brands are really reselling the same NetNut pool.

What should smart home users do now?
Consumers can reduce risk by keeping devices updated, avoiding suspicious applications, and researching manufacturers before purchasing connected hardware. Security settings should be reviewed regularly, especially for devices connected directly to home networks.
Streaming devices, smart TVs, and other internet-connected products should be treated as computers with security needs. A device placed in a living room can still create problems if its software allows unauthorized access.
The NetNut case serves as a reminder that smart home security depends on every connected product. Even a small streaming box can become part of a much larger cyber operation when attackers find a way to control it.
TL;DR
- According to Google, NetNut’s residential proxy network allegedly used at least 2 million consumer devices worldwide as hidden traffic relays for cybercrime operations.
- Low-cost Android TV boxes and streaming hardware reportedly became targets because they could provide anonymous residential internet access.
- Attackers allegedly used proxy exit nodes for password spraying, espionage activity, and ad fraud campaigns.
- Google worked with the FBI and Lumen Technologies to disrupt the network and reduce available device capacity.
- Consumers can lower smart home risks by avoiding suspicious bandwidth-sharing apps and choosing trusted device manufacturers.
This article was made with AI assistance and human editing.
If you liked this, you might also like:
Trending Products
iRobot Roomba Plus 405 (G181) 2in1 ...
Tipdiy Robot Vacuum and Mop Combo,4...
iRobot Roomba 104 2in1 Vacuum &...
Tikom Robot Vacuum and Mop Cleaner ...
ILIFE Robot Vacuum
T2280+T2108
ILIFE V5s Pro Robot Vacuum and Mop ...
T2353111-T2126121
Lefant Robot Vacuum Cleaner M210, W...
