Your Smart TV May Have Been Routing Criminal Traffic
Google's Threat Intelligence Group, working alongside the FBI and networking firm Lumen, has significantly disrupted NetNut — a residential proxy network (a service that rents out real home internet addresses so that other people's traffic can be disguised as ordinary household browsing) that had quietly embedded itself into at least 2 million home devices, including smart TVs and streaming boxes, according to The Hacker News.
Here is what that means in practice: once NetNut's software lands on your device, it becomes an "exit node" — a doorway that other people's internet traffic flows through. Your home IP address gets credited for whatever that traffic does, whether it is credential stuffing (automated password-guessing attacks run against thousands of accounts at once) or hiding the location of espionage groups. In a single week last June, Google counted 316 distinct threat groups using suspected NetNut exit nodes.
The software arrives two ways: pre-installed on cheap off-brand hardware, or bundled into free apps that never clearly ask for your consent. Researchers tested over 20 apps carrying this software and found that not one of them showed users a consent prompt. NetNut's parent company, Israeli firm Alarum Technologies, rejects the botnet label and calls the research inaccurate. The researchers' testing tells a different story.
Google describes this as degradation, not elimination. NetNut runs a reseller program, so its network lives inside dozens of brands that look independent but draw from the same pool.
What you should do: Check your home network's device list for anything unfamiliar — especially cheap streaming sticks or off-brand smart TVs. If you bought a no-name streaming device cheaply, consider replacing it with a trusted brand. Running your router's connected-devices list monthly is a good habit regardless.
Sources

