FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.
AI Analysis
Technical Summary
NetNut, a residential proxy platform operated by Alarum Technologies, was seized by the FBI due to its association with the Popa botnet. The Popa botnet consists of over two million devices compromised by malware, often without the owners' knowledge or consent. The FBI's seizure targeted hundreds of domains used by NetNut to facilitate proxy services that leveraged these compromised devices. This action was taken after investigative reporting linked NetNut to the botnet, highlighting the abuse of residential proxies for malicious purposes.
Potential Impact
The Popa botnet's use of compromised devices as residential proxies potentially enables malicious actors to anonymize and scale cyberattacks, fraud, and other illicit activities. The seizure disrupts the botnet's command and control infrastructure, reducing the threat posed by this large network of infected devices. However, the underlying malware infections on devices remain a concern for victims.
Mitigation Recommendations
The FBI seizure of NetNut domains effectively disrupts the botnet's proxy infrastructure. No direct patch or fix applies to end users from this action. Users should ensure their devices are secured against malware infections through standard endpoint protection measures. Monitor vendor advisories for any updates related to this threat. Since this is a law enforcement action against infrastructure, no software patch is applicable.
FBI Seizes NetNut Proxy Platform, Popa Botnet
Description
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
NetNut, a residential proxy platform operated by Alarum Technologies, was seized by the FBI due to its association with the Popa botnet. The Popa botnet consists of over two million devices compromised by malware, often without the owners' knowledge or consent. The FBI's seizure targeted hundreds of domains used by NetNut to facilitate proxy services that leveraged these compromised devices. This action was taken after investigative reporting linked NetNut to the botnet, highlighting the abuse of residential proxies for malicious purposes.
Potential Impact
The Popa botnet's use of compromised devices as residential proxies potentially enables malicious actors to anonymize and scale cyberattacks, fraud, and other illicit activities. The seizure disrupts the botnet's command and control infrastructure, reducing the threat posed by this large network of infected devices. However, the underlying malware infections on devices remain a concern for victims.
Defensive Guidance
The FBI seizure of NetNut domains effectively disrupts the botnet's proxy infrastructure. No direct patch or fix applies to end users from this action. Users should ensure their devices are secured against malware infections through standard endpoint protection measures. Monitor vendor advisories for any updates related to this threat. Since this is a law enforcement action against infrastructure, no software patch is applicable.
Technical Details
- Article Source
- {"url":"https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/","fetched":true,"fetchedAt":"2026-07-03T01:20:29.624Z","wordCount":1649}
- Classification
- {"confidence":0.69,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a470e5d27e9c7971998f196
Added to database: 07/03/2026, 01:20:29 UTC
Last enriched: 07/30/2026, 15:52:21 UTC
Last updated: 08/15/2026, 18:18:24 UTC
Views: 188
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.