{"id":960,"date":"2026-07-06T12:29:44","date_gmt":"2026-07-06T06:59:44","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=960"},"modified":"2026-08-19T12:40:48","modified_gmt":"2026-08-19T07:10:48","slug":"google-fbi-netnut-takedown","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/","title":{"rendered":"Google FBI NetNut Takedown: What Enterprises Should Learn from the NetNut Residential Proxy Disruption"},"content":{"rendered":"<h2>Google and the FBI Disrupt a Major Residential Proxy Network<\/h2>\n<p>The Google FBI NetNut takedown marks a significant effort to disrupt a residential proxy network that had reportedly become a key piece of infrastructure for modern identity attacks. Google, in coordination with the FBI and industry partners, targeted NetNut, also tracked as Popa, a residential proxy network allegedly powered by more than two million compromised Android devices.<\/p>\n<p>Many of the affected devices reportedly included smart TVs, streaming boxes, and other Android-based hardware that became proxy nodes after users installed trojanized applications or malware associated with Badbox 2.0. Instead of relying on servers hosted in cloud environments, the network routed traffic through real consumer internet connections, making malicious activity appear more legitimate.<\/p>\n<p>Google reported observing 316 distinct threat clusters using NetNut during a single week in June 2026. The infrastructure was reportedly used to disguise attacker locations during password spray attacks and attempts to access victim environments.<\/p>\n<p>As part of the coordinated operation, Google disabled Google accounts and services reportedly used for command-and-control, shared technical intelligence on NetNut SDKs and backend C2 infrastructure, disabled known applications through Google Play Protect, warned affected users, and shared intelligence with law enforcement and industry partners.<\/p>\n<p>While the operation significantly degraded NetNut&#8217;s infrastructure, it also underscores a broader security trend: residential proxy networks have become an increasingly common tool for threat actors seeking to obscure the origin of malicious authentication activity and other cyberattacks.<\/p>\n<h2>Why Residential Proxy Networks Matter for Enterprise Security<\/h2>\n<p>Unlike traditional proxy services hosted in cloud providers or data centers, residential proxy networks route traffic through real consumer devices connected to home internet services.<\/p>\n<p>This presents a challenge for enterprise defenders because authentication requests originating from residential IP addresses often appear more legitimate than traffic from known hosting providers.<\/p>\n<p>Threat actors commonly use residential proxy infrastructure to support activities such as:<\/p>\n<ul>\n<li>Password spray attacks<\/li>\n<li>Attempts to access victim environments using disguised residential traffic.<\/li>\n<\/ul>\n<p>The public reporting on NetNut confirms that password spray activity was observed using the network. However, it does not publicly confirm whether those attempts resulted in successful account compromise or data theft.<\/p>\n<p>For security teams, this distinction is important. The proxy network itself is not the attack. It is infrastructure that helps attackers conceal where their traffic originates, making malicious authentication attempts more difficult to distinguish from legitimate user activity.<\/p>\n<h2>What the Google-FBI Takedown Means for Enterprise Defenders<\/h2>\n<p>In this case, coordinated action between Google, law enforcement, and industry partners appears to have significantly degraded NetNut\u2019s proxy network.<\/p>\n<p>However, takedowns rarely eliminate the broader threat.<\/p>\n<p>Residential proxy ecosystems are highly distributed, and infrastructure may be rebuilt or replaced using newly compromised devices or alternative proxy services. This means organizations cannot rely solely on infrastructure disruptions to reduce risk.<\/p>\n<p>Instead, enterprises should assume that attackers will continue attempting to disguise authentication traffic using residential IP addresses and focus on strengthening defensive controls that remain effective regardless of where login requests originate.<\/p>\n<p>Rather than relying exclusively on IP reputation, organizations should adopt a layered identity security strategy that includes:<\/p>\n<ul>\n<li>Multi-factor authentication (<a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-multi-factor-authentication-mfa\/\">MFA<\/a>)<\/li>\n<li>Strong password policies and passwordless authentication where appropriate<\/li>\n<li>Device compliance validation before granting access<\/li>\n<li>Monitoring authentication activity for unusual patterns<\/li>\n<li>Investigating endpoint behavior when suspicious access attempts occur<\/li>\n<\/ul>\n<p>These measures can help reduce the effectiveness of <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-password-spraying\/\">password spray<\/a> campaigns even when attackers leverage seemingly legitimate residential infrastructure.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/xdr-and-zero-trust-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>XDR and Zero Trust: Securing Endpoints Together<\/h4><p>Learn how combining XDR with Zero Trust strengthens endpoint security through continuous visibility.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/xdr-zero-trust-endpoint-security\/\" aria-label=\"XDR and Zero Trust: Securing Endpoints Together\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Enterprises Can Reduce Proxy-Assisted Identity Risk<\/h2>\n<p>The NetNut disruption reinforces that identity security and endpoint security should work together rather than operate independently.<\/p>\n<p>Organizations can strengthen their security posture by:<\/p>\n<h3>Enforcing Managed Device Compliance<\/h3>\n<p>Ensuring only compliant, managed devices can access corporate resources helps reduce risks associated with unmanaged or outdated endpoints.<\/p>\n<h3>Keeping Endpoints Up to Date<\/h3>\n<p>Regular operating system updates and timely patch management reduce the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-a-cybersecurity-attack-surface\/\">attack surface<\/a> that malware may exploit.<\/p>\n<h3>Strengthening Authentication Controls<\/h3>\n<p>Combining MFA with role-based access controls and least-privilege principles can reduce the risk of password spray attempts leading to unauthorized access.<\/p>\n<h3>Investigating Suspicious Endpoint Activity<\/h3>\n<p>When unusual authentication events occur, endpoint investigations can provide additional context by revealing endpoint events, running processes, or query-based endpoint data on managed devices.<\/p>\n<h3>Maintaining Visibility Across the Endpoint Fleet<\/h3>\n<p>Comprehensive endpoint management allows IT teams to identify non-compliant devices and enforce security policies across managed endpoints.<\/p>\n<h2>How Hexnode Can Help<\/h2>\n<p>While no endpoint management platform can prevent attackers from operating external residential proxy networks, <a href=\"https:\/\/www.hexnode.com\/\">Hexnode<\/a> can help organizations strengthen the controls that reduce enterprise risk.<\/p>\n<h3>Hexnode UEM<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> enables organizations to:<\/p>\n<ul>\n<li>Enforce operating system update policies<\/li>\n<li>Verify device encryption status<\/li>\n<li>Manage approved applications<\/li>\n<li>Apply compliance policies across managed devices<\/li>\n<\/ul>\n<p>These capabilities help organizations maintain a managed and compliant endpoint fleet.<\/p>\n<h3>Hexnode IdP<\/h3>\n<p>Hexnode IdP supports identity security by enabling organizations to:<\/p>\n<ul>\n<li>Enforce multi-factor authentication<\/li>\n<li>Implement role-based access control (RBAC)<\/li>\n<li>Federate with enterprise identity providers such as Microsoft Entra ID and Google Workspace.<\/li>\n<li>Apply basic conditional access using device compliance information from Hexnode UEM<\/li>\n<\/ul>\n<p>When paired with supported identity and conditional access integrations, these capabilities can help organizations enforce access policies based on user identity and device compliance.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp 287w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1-96x100.webp?format=webp 96w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" title=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how integrating UEM with XDR enhances endpoint visibility, investigation, and response for a stronger security posture.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h3>Hexnode XDR<\/h3>\n<p>If suspicious endpoint activity is identified following authentication events, <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can support investigations through:<\/p>\n<ul>\n<li>Endpoint-focused detection<\/li>\n<li>Endpoint events<\/li>\n<li>Query-based investigations<\/li>\n<li>Response actions including device isolation, process termination, and file quarantine.<\/li>\n<\/ul>\n<p>These capabilities can help security teams investigate endpoint activity and take supported response actions on managed endpoints.<\/p>\n<h3>Conclusion<\/h3>\n<p>The <a href=\"https:\/\/www.securityweek.com\/google-fbi-disrupt-netnut-residential-proxy-network-powered-by-millions-of-devices\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=google_fbi_netnut_takedown\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Google and FBI disruption of NetNut<\/a> represents more than the takedown of a single residential proxy network. It highlights how identity attacks increasingly rely on trusted-looking infrastructure rather than obviously malicious servers.<\/p>\n<p>As attackers continue to disguise password spray activity behind residential IP addresses, enterprises should move beyond traditional IP-based detection. Strengthening authentication controls, validating device compliance, and maintaining visibility into endpoint activity provide a more resilient defense against proxy-assisted identity attacks.<\/p>\n<p>While infrastructure takedowns can disrupt malicious operations, long-term resilience depends on layered security controls that make enterprise environments harder to compromise regardless of where attack traffic originates.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Take Control of Your Enterprise Security<\/h5><p>Explore how Hexnode helps IT and security teams manage endpoints from a single platform.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google and the FBI Disrupt a Major Residential Proxy Network The Google FBI NetNut takedown&#8230;<\/p>\n","protected":false},"author":4,"featured_media":963,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,20],"class_list":["post-960","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-network-and-vpn","product_category-identity-provider","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Google FBI NetNut Takedown on a Residential Proxy Network<\/title>\n<meta name=\"description\" content=\"Learn how the Google FBI NetNut takedown disrupted a residential proxy network used in password spray attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google FBI NetNut Takedown on a Residential Proxy Network\" \/>\n<meta property=\"og:description\" content=\"Learn how the Google FBI NetNut takedown disrupted a residential proxy network used in password spray attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-06T06:59:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T07:10:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Google-FBI-NetNut-Takedown.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1350\" \/>\n\t<meta property=\"og:image:height\" content=\"759\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Google FBI NetNut Takedown: What Enterprises Should Learn from the NetNut Residential Proxy Disruption\",\"datePublished\":\"2026-07-06T06:59:44+00:00\",\"dateModified\":\"2026-08-19T07:10:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/\"},\"wordCount\":1008,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Google-FBI-NetNut-Takedown.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Network and VPN\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/\",\"name\":\"Google FBI NetNut Takedown on a Residential Proxy Network\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Google-FBI-NetNut-Takedown.jpeg?format=webp\",\"datePublished\":\"2026-07-06T06:59:44+00:00\",\"dateModified\":\"2026-08-19T07:10:48+00:00\",\"description\":\"Learn how the Google FBI NetNut takedown disrupted a residential proxy network used in password spray attacks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Google-FBI-NetNut-Takedown.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Google-FBI-NetNut-Takedown.jpeg?format=webp\",\"width\":1350,\"height\":759,\"caption\":\"Google FBI NetNut Takedown\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/google-fbi-netnut-takedown\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Google FBI NetNut Takedown: What Enterprises Should Learn from the NetNut Residential Proxy Disruption\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Google FBI NetNut Takedown on a Residential Proxy Network","description":"Learn how the Google FBI NetNut takedown disrupted a residential proxy network used in password spray attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/","og_locale":"en_US","og_type":"article","og_title":"Google FBI NetNut Takedown on a Residential Proxy Network","og_description":"Learn how the Google FBI NetNut takedown disrupted a residential proxy network used in password spray attacks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-06T06:59:44+00:00","article_modified_time":"2026-08-19T07:10:48+00:00","og_image":[{"width":1350,"height":759,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Google-FBI-NetNut-Takedown.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Google FBI NetNut Takedown: What Enterprises Should Learn from the NetNut Residential Proxy Disruption","datePublished":"2026-07-06T06:59:44+00:00","dateModified":"2026-08-19T07:10:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/"},"wordCount":1008,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Google-FBI-NetNut-Takedown.jpeg?format=webp","articleSection":["Identity Abuse","Network and VPN"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/","url":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/","name":"Google FBI NetNut Takedown on a Residential Proxy Network","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Google-FBI-NetNut-Takedown.jpeg?format=webp","datePublished":"2026-07-06T06:59:44+00:00","dateModified":"2026-08-19T07:10:48+00:00","description":"Learn how the Google FBI NetNut takedown disrupted a residential proxy network used in password spray attacks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Google-FBI-NetNut-Takedown.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Google-FBI-NetNut-Takedown.jpeg?format=webp","width":1350,"height":759,"caption":"Google FBI NetNut Takedown"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/google-fbi-netnut-takedown\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Google FBI NetNut Takedown: What Enterprises Should Learn from the NetNut Residential Proxy Disruption"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/960","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=960"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/960\/revisions"}],"predecessor-version":[{"id":976,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/960\/revisions\/976"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/963"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=960"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=960"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}