NetNut botnet takedown: how cheap Android TV sticks fueled massive cyberattacks

9

Your living room TV isn’t just streaming Netflix.
It’s hiding a criminal operation.

The FBI just took down NetNut, a residential proxy network that silently hijacked nearly two million home devices.
Most of them? Cheap Android TV boxes you could find on Amazon or Temu last week.
This wasn’t some obscure underground dark web ring. NetNut operated in the open. They sold access to this massive botnet as if it were a standard enterprise service.
Now the site is gone. An FBI seizure notice hangs in the digital void.
But the real story here is how easily everyday tech turned into a weapon.

How the NetNut residential proxy network worked

NetNut was one of the world’s largest providers of residential proxy services.
On paper, these services have legal uses. Businesses use them for ad verification. Or penetration testing. They need traffic to look like it’s coming from a regular person’s house, not a data center, to avoid being blocked by websites.

The twist?
The source of that “residential” IP address.
Instead of legitimate volunteers, NetNut was relying on a botnet known as Popa (and earlier, Vo1d ).
Security researchers at XLab first uncovered this mess in 2024.
They found off-brand Android TV sticks being hacked en masse.
These devices weren’t just playing ads. They were acting as intermediary servers.
When a criminal wanted to mask their identity, the request bounced through your hacked TV. To the target website, the attack looked like it came from the guy in the apartment next door.

This setup made traditional security useless.
Why? Because the traffic looked normal. It originated from valid, real-world IP addresses assigned by ISPs to households.
Google confirmed that the takedown degraded the network significantly, reducing the pool of hijacked devices by millions.
But Google admitted it’s not over.
Botnets share capacity. Take down one operator, and the bad guys just buy proxies from another.
As Google noted, they have to target interconnected providers simultaneously to actually win.

Which devices are at risk?

Not every smart device is vulnerable.
But the Vo1d botnet targeted specific hardware.
Namely: the budget-friendly Android TV streamers.
You know the kind. The ones sold by nameless brands on AliExpress, Amazon, or social media ads featuring influencers promising “free TV, no subscriptions.”

These boxes often run ancient, unsupported versions of Android.
No security patches.
No modern protections.
And here is the kicker:
Many of them arrived prehacked.
Researchers found malware installed at the factory or in the shipping phase.
You plug it in, and boom—your device joins a criminal proxy network before you’ve even turned on the TV.

Some of these hacked units were even blamed for a viral incident involving a fake AI video of Donald Trump appearing at the Department of Housing andUrban Development.
That was the Vo1d botnet showing its muscles.
Now, with NetNut dismantled, those devices might be sitting dormant. Or ready for a new command.

Why cheap smart home devices invite cyberattacks

Why does this happen?
Price.
Legitimate Android TV sticks from Google, Nvidia, or Sony cost money. They support long-term updates.
The knock-offs? They’re dirt cheap.
But you pay for that discount with security.

Manufacturers of these budget devices often skip essential security steps to hit a lower price point.
They don’t update the firmware.
They don’t sign their software properly.
They leave default credentials intact.

Cybercriminals love this.
It’s an easy entry point.
Once inside, the botnet operator can do more than just mask IP addresses.
They can scrape passwords. They can harvest sensitive data stored on the device.
They can spray credentials against other accounts linked to that user.

The risk isn’t just about your TV being slow. It’s about your home internet becoming a launchpad for illegal activity that you never authorized.

How to avoid joining the next botnet

You can’t fix NetNut.
But you can make sure your living room isn’t part of the next one.
Start with the hardware.
Stop buying from Instagram influencers promoting “free streaming” boxes.
If it sounds too good to be true, it probably has malware preloaded.
Stick to reputable brands. Sony. Nvidia. Amazon Fire TV. Roku. Google Chromecast with Google TV.
Check the specs. Does it get Android TV updates? If the answer is “I don’t know,” walk away.

This advice extends beyond TV sticks.
Smart lights. Smart thermostats. Cameras.
If it connects to Wi-Fi, it’s a potential node in a proxy network.
Change the default password.
Keep firmware updated.

There is also a newer threat called promptware.
This malware doesn’t just use your internet connection.
It tries to manipulate the on-board AI features of devices.
It’s getting creative.

Security is boring until it’s broken.
By then, it’s already too late to change your settings.
So update before the hackers do.

What else is running in your home network right now?