Is Your Smart TV Hiding a Cybercriminal Network?

Google and FBI Take Down NetNut Proxy Network That Turned Smart TVs Into Criminal Cover

Google, working with the FBI, network operator Lumen, and other cybersecurity partners, has disrupted a massive proxy network known as NetNut, also referred to as Popa. The case stands out because it did not only involve traditional computers or servers. Many of the affected devices were ordinary smart TVs and streaming boxes sitting inside people’s homes.

According to estimates from the Google Threat Intelligence Group, the NetNut network involved at least two million devices worldwide. Many owners likely had no idea their home electronics were being used to route suspicious or criminal internet traffic.

How a smart TV can become part of a proxy network

A residential proxy network works by routing internet traffic through real home IP addresses. To outsiders, that traffic appears to come from a normal household connection rather than from a data center, criminal server, or suspicious location.

That makes residential proxies attractive to cybercriminals. They can use them to hide their identity, bypass security filters, carry out fraud, launch password attacks, scrape websites, or mask espionage activity.

For this to happen, hidden code must run on as many home devices as possible. In the NetNut case, that code was reportedly distributed through software development kits, commonly called SDKs. These SDKs can be embedded inside apps or firmware used by smart TVs, Android TV boxes, and streaming devices.

In some cases, the proxy code may have been installed before the device was even sold. In others, users may have downloaded an app without realizing it contained background software designed to turn their device into an exit node for someone else’s traffic.

Why this is risky for home users

If your smart TV or streaming box becomes part of a proxy network, your home internet connection may be used by strangers. That means your IP address could appear to be the source of activity you did not perform.

This can create several problems. Your internet provider, websites, or online services may flag your connection as suspicious. You may experience blocked logins, CAPTCHA challenges, account restrictions, or trouble accessing services that think your IP address is linked to abuse.

The danger may not stop there. A compromised streaming device on your home network could also give attackers a foothold to scan or target other connected devices, including phones, laptops, routers, smart cameras, or storage devices.

Google reported that in just one week in June 2026, 316 different attacker groups used NetNut nodes. These included financially motivated cybercriminals as well as groups linked to espionage activity. Security researchers also found that NetNut infrastructure was used to infect devices with variants of the Mirai botnet, a well-known malware family often associated with large-scale DDoS attacks.

What Google did to disrupt NetNut

Google says it blocked the accounts and services used by NetNut operators to control the malware. It also shared technical information about the related SDKs, apps, and infrastructure with law enforcement agencies and cybersecurity companies.

Google Play Protect, the built-in security system for Android devices, has also been updated to detect apps containing NetNut-related code. When such apps are found, Play Protect can warn users and disable the threat automatically.

According to Google, these actions reduced the available pool of compromised devices by millions. However, the company warned that the problem may not disappear completely. NetNut reportedly operated through a reseller model, allowing other providers to sell access to the same type of compromised device network under different names. If one network weakens, operators may attempt to buy capacity from similar services.

How to protect your smart TV and streaming devices

The NetNut takedown is a reminder that smart TVs and streaming boxes should be treated like any other internet-connected device. They need regular updates, safe apps, and basic security checks.

Avoid apps that offer money or rewards in exchange for sharing unused internet bandwidth. These services may look harmless, but they can turn your connection into part of a proxy network.

Install apps only from official app stores whenever possible. Be especially careful with third-party VPN, proxy, “free streaming,” or bandwidth-sharing apps, as these categories are often abused by bad actors.

Keep Google Play Protect enabled on Android-based devices. This can help detect and disable harmful apps before they create bigger problems.

Buy streaming boxes, smart TVs, and set-top boxes from reputable brands. Extremely cheap Android TV boxes from unknown manufacturers may come with outdated software, weak security, or unwanted code already installed.

Check whether your Android TV or streaming device is Play Protect certified. Certified devices are more likely to meet Google’s security and compatibility requirements.

Keep your router, smart TV, and streaming box updated with the latest firmware. Updates often patch security weaknesses that attackers use to gain access.

If your home internet connection is suddenly being blocked by websites, showing unusual CAPTCHA requests, or triggering suspicious activity warnings, review the apps installed on your smart TV and streaming devices. Removing unknown apps and resetting the device may help if you suspect compromise.

The bigger lesson from the NetNut case

The disruption of NetNut shows how cybercriminals are increasingly targeting everyday household devices, not just computers and phones. A smart TV may seem harmless, but if it runs hidden proxy software, it can become a tool for fraud, hacking, and botnet activity.

As more homes fill with internet-connected devices, users need to be more selective about what they buy and install. A cheap streaming box or unknown app can come with hidden costs, especially if it quietly allows outsiders to use your home internet connection as cover for criminal activity.