Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Google’s Continued Disruption of Malicious Residential Proxy Networks

Google, the FBI, and Lumen jointly dismantled the NetNut (Popa) residential proxy network, building on January's IPIDEA takedown — offering defenders fresh intelligence on proxy infrastructure used for credential stuffing and fraud.

Summary written by editorial AI · Source link below

Filed by Google Threat Intel1 min readRead at source ↗

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following actions: Disabled Google accounts and associated Google services used by NetNut for malwar

Editorial Analysis

Why it matters

Residential proxies mask attack traffic as legitimate consumer connections, making detection harder; each takedown provides a window to update IP reputation data before operators rebuild.

What to do

Update IP reputation and anti-bot systems with IOCs from the NetNut takedown and monitor for migration to successor proxy networks.

Board brief

A major residential proxy network used for fraud and credential attacks was dismantled — update your defences before successor infrastructure appears.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Google Threat Intel

External link — opens at Google Threat Intel in a new tab.

§
Continue with

More from the Threat Intel Desk