Skip to main content

FBI Seizes NetNut Proxy Platform, Popa Botnet

0
Medium
Published: 07/02/2026 (07/02/2026, 19:27:33 UTC)
Source: Krebs on Security

Description

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut , a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. The NetNut homepage today was replaced by this seizure banner from the FBI. On June 19, three different security firms issued similar findings : That NetNut is a residential proxy network which populates a botnet called Popa, and distributes software for devices commonly found in homes, such as smart TVs and streaming boxes. NetNut’s software turns those systems into always-on residential proxy nodes that are rented to others, who predominantly use them to relay abusive and intrusive Internet traffic, such as mass content scraping, advertising fraud, and account takeover activity. Earlier today, NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The seizure notice thanked Google , Lumen , Shadowserver and other industry partners for their help in dismantling hundreds of domains tied to the Popa botnet, which experts say has long been synonymous with NetNut’s residential proxy infrastructure. In a blog post published today, the Google Threat Intelligence Group (GTIG) said NetNut’s proxy network is widely resold and white-labeled by a number of third-party proxy providers, and that its services are heavily sought out by cybercriminals seeking to obfuscate the source of their malicious traffic. The GTIG said that in a single week during June 2026, they observed 316 distinct clusters of threat actors using suspected NetNut exit nodes, including cybercriminal and espionage groups. “These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,” Google’s GTIG wrote . “Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.” Google said it disabled Google accounts and services used by NetNut for malware command and control, and that it shared technical intelligence on NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement and research firms. The company also disabled apps known to bundle NetNut’s various SDKs. Omer Weiss , legal counsel for NetNut parent Alarum Technologies, said the company was aware of the FBI seizure and cooperating with investigators. “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,” Weiss said in a written statement. Benjamin Brundage is founder of the proxy tracking service Synthient , one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies. Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it. Brundage said NetNut’s apparent demise is likely to be a great disadvantage for the cybercrime community, which was already reeling from legal actions by Google earlier this year that seized infrastructure for NetNut’s biggest competitor — IPIDEA . “I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,” he said. “Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily tr…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 15:52:21 UTC

Technical Analysis

NetNut, a residential proxy platform operated by Alarum Technologies, was seized by the FBI due to its association with the Popa botnet. The Popa botnet consists of over two million devices compromised by malware, often without the owners' knowledge or consent. The FBI's seizure targeted hundreds of domains used by NetNut to facilitate proxy services that leveraged these compromised devices. This action was taken after investigative reporting linked NetNut to the botnet, highlighting the abuse of residential proxies for malicious purposes.

Potential Impact

The Popa botnet's use of compromised devices as residential proxies potentially enables malicious actors to anonymize and scale cyberattacks, fraud, and other illicit activities. The seizure disrupts the botnet's command and control infrastructure, reducing the threat posed by this large network of infected devices. However, the underlying malware infections on devices remain a concern for victims.

Defensive Guidance

The FBI seizure of NetNut domains effectively disrupts the botnet's proxy infrastructure. No direct patch or fix applies to end users from this action. Users should ensure their devices are secured against malware infections through standard endpoint protection measures. Monitor vendor advisories for any updates related to this threat. Since this is a law enforcement action against infrastructure, no software patch is applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/","fetched":true,"fetchedAt":"2026-07-03T01:20:29.624Z","wordCount":1649}
Classification
{"confidence":0.69,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a470e5d27e9c7971998f196

Added to database: 07/03/2026, 01:20:29 UTC

Last enriched: 07/30/2026, 15:52:21 UTC

Last updated: 10/01/2026, 11:26:25 UTC

Views: 268

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses