NetNut, also tracked as Popa, was a large malicious residential proxy network backed by a botnet of compromised Android consumer devices, including smart TVs, streaming boxes, set-top devices, and other home-connected systems. It functioned as a for-hire proxy service that routed customer traffic through infected residential devices, allowing downstream users to mask malicious activity behind legitimate household IP addresses. Security reporting in 2026 described NetNut as one of the largest and most widely used malicious residential proxy networks, with estimates ranging from roughly 1.5 million daily IPs to at least 2 million infected devices globally. The network was associated with a substantial backend infrastructure, including command-and-control and gateway systems, and operated a reseller and white-label model that enabled other proxy brands and criminal services to resell its capacity. This made NetNut part of a broader, interconnected proxy ecosystem in which operators both maintained their own botnets and traded access to compromised-device pools. NetNut’s device base was linked to trojanized applications, embedded SDK components, and botnet activity affecting Android-based consumer hardware. It was also tied to broader malware ecosystems, including Badbox 2.0, and was observed being leveraged by both cybercriminal and espionage-linked clusters. Reported use cases included hiding access to attacker infrastructure, password-spraying, and facilitating intrusion activity against victim environments. Separate reporting also documented NetNut capacity being resold by other proxy services and associated with downstream abuse such as Mirai-related botnet activity. In 2026, a coordinated disruption involving Google, the FBI, Lumen Technologies, Shadowserver, and other partners targeted NetNut’s infrastructure, operator-controlled services, and malware distribution mechanisms. Defensive actions included seizure of operator infrastructure, disabling command-and-control services, and blocking or warning on Android applications that bundled NetNut-related components. Known alias: Popa.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious residential proxy operation with large-scale botnet-backed infrastructure and reseller relationships, disrupted but still notable in the ecosystem.
Operates a large residential proxy botnet built from compromised Android devices, including smart TVs and streaming boxes, enabling cybercriminal and espionage activity by routing malicious traffic through victims' residential IP addresses.
Operator of a large malicious residential proxy network that conscripted millions of home devices into a for-hire network used by cybercriminal and espionage actors to mask origin, support intrusions, and conduct password-spraying.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.