Google’s Continued Disruption of Malicious Residential Proxy Networks
Google, the FBI, and Lumen jointly dismantled the NetNut (Popa) residential proxy network, building on January's IPIDEA takedown — offering defenders fresh intelligence on proxy infrastructure used for credential stuffing and fraud.
Summary written by editorial AI · Source link below
Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malwar
Editorial Analysis
Residential proxies mask attack traffic as legitimate consumer connections, making detection harder; each takedown provides a window to update IP reputation data before operators rebuild.
Update IP reputation and anti-bot systems with IOCs from the NetNut takedown and monitor for migration to successor proxy networks.
A major residential proxy network used for fraud and credential attacks was dismantled — update your defences before successor infrastructure appears.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Google Threat Intel in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d