Smart TVs: Hidden Tools for Criminal Activity Uncovered

Key Takeaways

  • Google, in collaboration with the FBI and Lumen, has dismantled the NetNut proxy network, which compromised millions of smart devices.
  • The malware utilized ordinary home devices, including smart TVs, as exit nodes for cybercriminal activities.
  • Google has implemented protective measures, but risks remain as operators may resell access to the botnet.

Proxy Network Shutdown Details

Google has taken significant action against the NetNut proxy network, also known as Popa, in partnership with the FBI, Lumen, and other organizations. This network was particularly alarming as it leveraged ordinary household devices, primarily smart TVs and streaming boxes, turning them into nodes for malicious activities. An estimate from the Google Threat Intelligence Group suggests that NetNut affected at least two million devices globally.

NetNut operated as a residential proxy network that allowed cybercriminals to conceal their identity by routing traffic through residential IP addresses. For this system to function, malicious code was installed on numerous home devices, either pre-installed or downloaded unknowingly through compromised applications. This exploitation enabled attackers to use households’ internet connections for various illicit activities, including launching password attacks and fraud.

In one week alone in June 2026, Google observed 316 different attacker groups utilizing NetNut’s infrastructure for cyber attacks, including tactics related to the Mirai DDoS botnet. In response, Google has blocked the operational accounts linked to NetNut and shared critical technical data with law enforcement and cybersecurity firms. The Google Play Protect feature has also begun automatically identifying and disabling apps containing the malicious code, significantly reducing the number of compromised devices.

Despite these efforts, the threat persists as NetNut’s reseller program allows other providers to rent out similar botnet capabilities. To safeguard personal devices, users are advised to be wary of apps that incentivize sharing unused bandwidth, only download from official sources, and verify the security certifications of their devices. Keeping Google Play Protect enabled is crucial for maintaining device security.

The content above is a summary. For more details, see the source article.

Leave a Comment

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Become a member

RELATED NEWS

Become a member

Scroll to Top