{"id":6683,"date":"2026-07-21T10:53:26","date_gmt":"2026-07-21T10:53:26","guid":{"rendered":"https:\/\/lockitsoft.com\/?p=6683"},"modified":"2026-07-21T10:53:26","modified_gmt":"2026-07-21T10:53:26","slug":"fbi-and-industry-partners-dismantle-netnut-residential-proxy-network-linked-to-popa-botnet","status":"publish","type":"post","link":"https:\/\/lockitsoft.com\/?p=6683","title":{"rendered":"FBI and Industry Partners Dismantle NetNut Residential Proxy Network Linked to Popa Botnet"},"content":{"rendered":"<p>The Federal Bureau of Investigation (FBI), in collaboration with a coalition of industry partners, announced today the successful seizure of hundreds of internet domains associated with NetNut, a prominent residential proxy service operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). This significant enforcement action, occurring approximately two weeks after investigative reporting by KrebsOnSecurity detailed connections between NetNut and the Popa botnet, marks a substantial blow against a sophisticated cybercriminal infrastructure. The Popa botnet, a vast network comprising at least two million compromised devices, has been operating with minimal or no consent from its victims, facilitating a wide range of illicit online activities.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/lockitsoft.com\/?p=6683\/#The_Genesis_of_the_Operation_Linking_NetNut_to_the_Popa_Botnet\" >The Genesis of the Operation: Linking NetNut to the Popa Botnet<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/lockitsoft.com\/?p=6683\/#Unpacking_NetNuts_Role_in_Cybercrime\" >Unpacking NetNut&#8217;s Role in Cybercrime<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/lockitsoft.com\/?p=6683\/#Official_Responses_and_Industry_Reactions\" >Official Responses and Industry Reactions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/lockitsoft.com\/?p=6683\/#Broader_Implications_for_Cybersecurity_and_the_Proxy_Market\" >Broader Implications for Cybersecurity and the Proxy Market<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/lockitsoft.com\/?p=6683\/#A_Persistent_Threat_Compromised_Devices_and_Smart_TV_Vulnerabilities\" >A Persistent Threat: Compromised Devices and Smart TV Vulnerabilities<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/lockitsoft.com\/?p=6683\/#Timeline_of_Events_and_Future_Outlook\" >Timeline of Events and Future Outlook<\/a><\/li><\/ul><\/nav><\/div>\n<h3><span class=\"ez-toc-section\" id=\"The_Genesis_of_the_Operation_Linking_NetNut_to_the_Popa_Botnet\"><\/span>The Genesis of the Operation: Linking NetNut to the Popa Botnet<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The coordinated takedown follows closely on the heels of independent findings released on June 19th by three distinct cybersecurity firms. These reports concurrently established that NetNut, a residential proxy network, was intrinsically linked to the Popa botnet. The investigation revealed that NetNut&#8217;s operations involved the distribution of software for devices commonly found in households, including smart televisions and streaming boxes. This software effectively transforms these consumer devices into perpetually active residential proxy nodes. These nodes are then leased to a clientele predominantly engaged in relaying abusive and intrusive internet traffic. Such traffic includes large-scale content scraping, sophisticated advertising fraud schemes, and malicious account takeover attempts.<\/p>\n<p>The impact of this operation was made starkly visible today, as the NetNut homepage was replaced by a prominent seizure banner from the FBI and the Internal Revenue Service Criminal Investigation (IRS-CI) division. This banner, a clear indicator of law enforcement intervention, also extended its gratitude to key industry partners, including Google, Lumen, and Shadowserver, for their instrumental contributions in dismantling the extensive network of domains tied to the Popa botnet. Cybersecurity experts have long identified the Popa botnet&#8217;s infrastructure as being synonymous with NetNut&#8217;s residential proxy services, underscoring the interconnectedness of the seized assets.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Unpacking_NetNuts_Role_in_Cybercrime\"><\/span>Unpacking NetNut&#8217;s Role in Cybercrime<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Google&#8217;s Threat Intelligence Group (GTIG), in a detailed blog post published concurrently with the seizure announcement, elaborated on NetNut&#8217;s pervasive role in the cybercrime ecosystem. GTIG confirmed that NetNut&#8217;s proxy network was widely resold and often white-labeled by numerous third-party proxy providers. This practice made NetNut&#8217;s services highly sought after by cybercriminals aiming to obscure the origins of their malicious traffic. The GTIG reported observing a staggering 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes within a single week in June 2026 alone. This diverse group included entities involved in both cybercriminal activities and espionage.<\/p>\n<p>&quot;These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks,&quot; Google&#8217;s GTIG stated in their published analysis. The report further highlighted the significant risks posed to ordinary consumers: &quot;Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.&quot;<\/p>\n<p>Google&#8217;s direct involvement in the operation included the disabling of Google accounts and services that NetNut had utilized for command and control of its malware infrastructure. The company also proactively shared critical technical intelligence concerning NetNut&#8217;s software development kits (SDKs) and backend infrastructure with various platform providers, law enforcement agencies, and research firms. Additionally, Google took action to disable applications known to bundle NetNut&#8217;s various SDKs, further disrupting its operational capabilities.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/netnutseizure.png\" alt=\"FBI Seizes NetNut Proxy Platform, Popa Botnet\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"Official_Responses_and_Industry_Reactions\"><\/span>Official Responses and Industry Reactions<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Omer Weiss, legal counsel for NetNut&#8217;s parent company, Alarum Technologies, acknowledged the FBI&#8217;s seizure and affirmed the company&#8217;s commitment to cooperating with investigators. &quot;Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account,&quot; Weiss stated in a written declaration. This statement suggests that Alarum Technologies is positioning itself as a party wronged by the misuse of its services, rather than a direct participant in the illicit activities facilitated by NetNut.<\/p>\n<p>Benjamin Brundage, founder of the proxy tracking service Synthient and one of the firms that published evidence linking the Popa botnet to NetNut and Alarum Technologies last month, provided an expert perspective on the immediate impact of the domain seizures. Brundage indicated that the action appears to have significantly disrupted both the Popa botnet and the underlying NetNut proxy network. He posited that the apparent demise of NetNut is likely to represent a considerable setback for the cybercrime community, which was already grappling with the aftermath of earlier legal actions taken by Google earlier this year. Those actions targeted the infrastructure of NetNut&#8217;s primary competitor, IPIDEA, a move that had propelled NetNut to increased prominence.<\/p>\n<p>&quot;I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,&quot; Brundage commented. He further elaborated on NetNut&#8217;s market position, stating, &quot;Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.&quot;<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Broader_Implications_for_Cybersecurity_and_the_Proxy_Market\"><\/span>Broader Implications for Cybersecurity and the Proxy Market<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The disruption of the NetNut and Popa botnet infrastructure may yield an additional significant benefit: a reduction in the potency of large-scale distributed denial-of-service (DDoS) botnets. These botnets have frequently leveraged poorly configured residential proxy services to amplify their attacks. Brundage recalled Synthient&#8217;s revelation in January concerning the Kimwolf botnet, which was identified as the world&#8217;s largest DDoS botnet. This botnet had exploited residential proxy connections, such as those provided by IPIDEA, to tunnel into the local networks of TV box owners, subsequently infecting other Android-based devices behind the victim&#8217;s firewall.<\/p>\n<p>While major proxy providers have reportedly taken steps to mitigate such activities, resellers of these networks have been notably slower to address the escalating threat. &quot;In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there,&quot; Brundage stated, anticipating a dampening effect on these large-scale attack vectors.<\/p>\n<p>Google&#8217;s assessment aligns with this view, estimating that today&#8217;s actions have resulted in &quot;significant degradation to NetNut&#8217;s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions.&quot; However, the company also issued a cautionary note, highlighting the resilience and adaptability of proxy networks. Google warns that these networks can reconstitute themselves by reselling capacity from other proxy services, a tactic that IPIDEA has demonstrably employed in recent months.<\/p>\n<p>&quot;Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,&quot; the GTIG report concluded. &quot;While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers.&quot;<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/07\/netnut-popa-blacklotus.png\" alt=\"FBI Seizes NetNut Proxy Platform, Popa Botnet\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"A_Persistent_Threat_Compromised_Devices_and_Smart_TV_Vulnerabilities\"><\/span>A Persistent Threat: Compromised Devices and Smart TV Vulnerabilities<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The issue of compromised consumer devices, particularly streaming boxes, remains a persistent concern. As KrebsOnSecurity has repeatedly warned, many unbranded TV streaming boxes available on major e-commerce platforms are either pre-installed with residential proxy software or necessitate the installation of proxy SDKs for their intended functionality, which often includes streaming unauthorized content. Google&#8217;s advice to consumers is to opt for reputable brands from trusted manufacturers and to exercise caution and judiciousness when installing applications on these devices.<\/p>\n<p>The compromised TV boxes implicated in the Popa botnet and other threats often run unofficial Android operating systems that bypass Google&#8217;s Play Protect certification. Consumers can verify the authenticity of their Android TV OS and Play Protect certification by consulting Google&#8217;s official support documentation.<\/p>\n<p>The threat extends beyond streaming boxes. Smart televisions from manufacturers like Samsung and LG can also become unwitting participants in residential proxy networks through the installation of third-party applications. A recent report from the proxy tracking company Spur revealed that a significant percentage of apps available for LG&#8217;s webOS operating system (42%) contain SDKs that transform the television into a residential proxy node. Similarly, over a quarter of apps designed for Samsung&#8217;s Tizen operating system were found to include comparable residential proxy components.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Timeline_of_Events_and_Future_Outlook\"><\/span>Timeline of Events and Future Outlook<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The sequence of events leading to this major enforcement action highlights the critical role of cybersecurity research and industry collaboration:<\/p>\n<ul>\n<li><strong>January 2026:<\/strong> Synthient reveals the Kimwolf botnet, demonstrating how compromised residential proxy networks can be exploited for large-scale DDoS attacks.<\/li>\n<li><strong>Early 2026:<\/strong> Google takes significant legal action against IPIDEA, a major competitor to NetNut, disrupting its infrastructure.<\/li>\n<li><strong>June 2026 (Week of June 19th):<\/strong> Three independent cybersecurity firms release parallel findings, linking NetNut to the Popa botnet and identifying its use of consumer devices as proxy nodes.<\/li>\n<li><strong>June 2026 (Following IPIDEA Takedown):<\/strong> NetNut reportedly experiences a surge in popularity and traffic as cybercriminals seek alternative proxy services.<\/li>\n<li><strong>July 2026 (Date of Article Publication):<\/strong> The FBI, IRS-CI, and industry partners, including Google, Lumen, and Shadowserver, execute a coordinated seizure of hundreds of NetNut domains. The NetNut and Alarum Technologies websites display seizure notices.<\/li>\n<li><strong>July 2026 (Post-Publication Update):<\/strong> Alarum Technologies&#8217; stock experiences a significant decline, reportedly around a 67% drop over the past week, trading at approximately $2.62 per share.<\/li>\n<\/ul>\n<p>While this operation represents a substantial victory against a key player in the residential proxy market, the dynamic nature of the cybercrime landscape suggests that efforts to rebuild and adapt will continue. The interconnectedness of proxy services means that disruptions to one can lead to the growth of others or the adoption of new business models. The ongoing challenge for law enforcement and cybersecurity firms will be to adapt their strategies to target the broader ecosystem of interconnected providers, ensuring a more lasting impact on the illicit use of residential proxy networks. The FBI&#8217;s action serves as a strong deterrent, but vigilance and continuous adaptation remain paramount in the fight against cybercrime.<\/p>\n<!-- RatingBintangAjaib -->","protected":false},"excerpt":{"rendered":"<p>The Federal Bureau of Investigation (FBI), in collaboration with a coalition of industry partners, announced today the successful seizure of hundreds of internet domains associated with NetNut, a prominent residential proxy service operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). This significant enforcement action, occurring approximately two weeks after investigative reporting by &hellip;<\/p>\n","protected":false},"author":9,"featured_media":6682,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[108],"tags":[1470,109,2539,709,1108,3130,1015,255,3132,111,2376,3131,110],"class_list":["post-6683","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-protection","tag-botnet","tag-cybersecurity","tag-dismantle","tag-industry","tag-linked","tag-netnut","tag-network","tag-partners","tag-popa","tag-privacy","tag-proxy","tag-residential","tag-security"],"_links":{"self":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/6683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6683"}],"version-history":[{"count":0,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/6683\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/media\/6682"}],"wp:attachment":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}