The images in this article were generated with artificial intelligence. How we publish
Google, in collaboration with the FBI and several infrastructure providers, has significantly degraded one of the largest residential proxies networks known as NetNut (also traced as Popa), an operation that converts domestic devices into leased relays for third-party traffic. The action temporarily reduces the network's capacity, but does not eliminate it: it reflects the distributed and commercial nature of these infrastructure, which remains resilient because it is sold and resold between operators.
One network of residential proxies It sells access to IP addresses that are really private homes, so those who pay for that access can route their traffic through domestic connections and avoid blockages applied to data center addresses. To form that pool, operators need software running on domestic devices: sometimes it comes pre-installed on cheap hardware, sometimes it is installed next to supposedly harmless applications. When a gadget acts as "output node," the external traffic enters your local network and any malicious activity is associated with your IP address, with consequences for privacy, security and, in some cases, legal responsibilities.

Public reports and platform intelligence show a correlation between NetNut / Popa and Alarum Technologies, listed in stock exchange. Researchers from different firms conducted controlled tests that suggest traffic roads through networked devices, and Google's own action is based on that signal convergence. Technical evidence can demonstrate the traffic route without necessarily proving the criminal intention of the service owners or resellers, which complicates public explanations and commercial defenses. For additional context on research and technical coverage, see Google's communication and analysis in specialized media such as The Hacker News and Google's intelligence team publications:
Google Threat Analysis Group and The Hacker News.
The implications are several and serious. For domestic users, the risk is not only slow or data consumption: your connection can be used to commit fraud, launch brute force attacks, send spam or perform espionage activities that leave track on your IP. For companies and platforms, these networks allow attackers to disguise their origin and avoid geographical and reputation controls. For regulators and law enforcement, the existence of a commercial layer that resells capacity complicates the attribution and judicial measures necessary to dismantle infrastructure.
Partial technical takedowns, such as the degradation that Google announced, work when actors who manage gateways or transit providers are blocked or removed from visibility, but these ecosystems are dynamic: operators can go on to buy capacity from other actors, override services or use distributor networks. This is why the most effective actions are often multilateral and combine technical blockages, court orders and coordinated commercial disruption efforts between platforms, ISPs and international entities.

If you have a home connected, there are practical measures that reduce the likelihood that a device will end up part of this type of network. Keep the router and device firmware up to date, change default passwords and use separate networks (e.g. a guest network for IoT devices). Download only official store applications, carefully check app permissions that promise to "share bandwidth" or pay for your connection, and keep the store and antivirus protections on the operating system. A recurring risk sign is an app that offers to pay for your "unused bandwidth": it is almost always an alert signal.
For network operators, platforms and corporate security officials, the recommendation is to increase cooperation: share commitment indicators, block suspicious commercial gateways on reputation lists, and monitor reemerging traffic under reselling brands. The authorities should also assess regulatory measures to make services that trade with residential routing capacity more transparent and improve traceability without jeopardizing legitimate privacy.
The most important lesson is that demand for residential IP addresses does not disappear with a single operation: when a network falls, activity tends to relocate under new brands or resale agreements. For users that means maintaining basic digital hygiene and for defenders and regulators means investing in cooperation between sectors to attack both the technical and commercial layers that support these networks.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...