LLevelNews
technologyAdvanced2 min read7/8/2026

Joint Operation Disrupts Large Proxy Network Linked to Cybercrime

The FBI and Google Threat Intelligence Group said they targeted a major proxy network that had powered cybercrime activity worldwide. The infrastructure, known to researchers as Popa botnet and sold as NetNut, was said to have affected more than 2 million devices and to have been significantly disrupted.

The FBI and Google Threat Intelligence Group carried out a joint operation against a large proxy network that had been used in cybercrime across the world. The infrastructure, known to security researchers as Popa botnet and operated as NetNut, was described as having reached more than 2 million devices. Researchers said it spread through low-cost Android-based smart TVs, TV boxes, and unofficial apps that carried a malicious software development kit. After infection, the devices became proxy exit points for attackers, often through residential connections, which made it easier to hide activity and reduce the chance of detection.

Google said that in just one week in June 2026, at least 316 different threat groups used the infrastructure for password theft, credential theft, ad fraud, and sensitive data collection. Investigators also said the system had a commercial structure, unlike classic botnets. During the operation, authorities seized hundreds of domain names, and Google disabled accounts used in the botnet's command-and-control system. Google Play Protect was also updated to detect the affected apps and disable applications that contained the harmful kit. Alarum Technologies, which was linked to NetNut, said it took the claims seriously and would cooperate fully with law enforcement.