VYPR
breachPublished Jul 2, 2026· Updated Jul 6, 2026· 9 sources

FBI Seizes NetNut Proxy Platform and Popa Botnet

The FBI, with industry partners, has seized hundreds of domains associated with NetNut, a residential proxy service linked to the Popa botnet, disrupting a major tool used by cybercriminals.

The Federal Bureau of Investigation (FBI), in collaboration with industry partners, announced the seizure of hundreds of domains associated with NetNut, a large-scale residential proxy service operated by the Israeli company Alarum Technologies. This action follows recent findings from multiple security firms that linked NetNut to the Popa botnet, a network comprising at least two million compromised devices.

NetNut's service functions by transforming compromised devices, including smart TVs and streaming boxes, into proxy nodes. These nodes are then rented out to cybercriminals who utilize them to mask their online activities. Common malicious uses include mass content scraping, advertising fraud, and account takeover operations. The FBI's seizure notice, which replaced NetNut's homepage, thanked key industry partners such as Google, Lumen, and Shadowserver for their assistance in dismantling the infrastructure.

Google Threat Intelligence Group (GTIG) observed that NetNut's proxy network is widely resold and white-labeled by numerous third-party providers. Cybercriminals heavily rely on these services to obscure the origin of their malicious traffic. In a single week during June 2026, GTIG identified 316 distinct clusters of threat actors using suspected NetNut exit nodes, encompassing both cybercriminal and espionage groups.

According to Google, these bad actors leverage NetNut to mask their origin IP addresses when accessing victim environments, their own infrastructure, or conducting password spray attacks. A significant concern highlighted by Google is that when a consumer device becomes an exit node, unauthorized network traffic passes through it, potentially exposing other private devices on the same home network to Internet threats.

In response, Google disabled accounts and services used by NetNut for command and control, and shared technical intelligence regarding NetNut's software development kits (SDKs) and backend infrastructure with law enforcement and research firms. The company also disabled applications known to bundle NetNut's SDKs.

NetNut's parent company, Alarum Technologies, did not respond to requests for comment. Prior to this seizure, Alarum had disputed characterizations of NetNut as a botnet and threatened legal action against those publishing reports that could damage its brand.

Benjamin Brundage, founder of the proxy tracking service Synthient, stated that the domain seizures have significantly disrupted both the Popa botnet and the NetNut proxy network. He noted that NetNut's demise is a major blow to the cybercrime community, especially following the earlier disruption of IPIDEA, NetNut's primary competitor. Brundage indicated that NetNut had gained substantial popularity after IPIDEA's takedown and was comparable in traffic, quality, size, and price.

The takedown is also expected to reduce the impact of large distributed denial-of-service (DDoS) botnets that have exploited poorly configured residential proxy services. Brundage mentioned that the compromise of TV boxes via proxy networks has fueled DDoS botnets like Kimwolf. While major proxy providers have taken steps to block such activity, resellers have been slower to respond. Google estimates that the action has caused significant degradation to NetNut's network and business operations, reducing the available pool of devices by millions, though they caution that proxy networks can rebuild by reselling services from competitors.

This new report from Google details its own "degradation" operation against the NetNut residential proxy network, which it identifies as also being known as Popa. Google's Threat Intelligence Group (GTIG) worked with the FBI and Lumen to reduce the network's usable devices by millions, estimating it had at least 2 million devices. The article further elaborates on how NetNut, owned by the publicly traded Israeli company Alarum Technologies, operates by embedding its code on home devices, often without clear user consent, and highlights that a single takedown is insufficient due to NetNut's reseller program.

This new article from Cyber Security News provides further details on the NetNut residential proxy takedown, specifically linking the "Popa" botnet to NetNut's SDKs and its reseller program. It highlights that NetNut is a subsidiary of Alarum Technologies Ltd (NASDAQ: ALAR) and details how the Popa botnet operates on unofficial Android TV boxes, often bundled with pirated streaming apps. The report also includes disputed claims from Alarum Technologies regarding consensual bandwidth sharing and counters with evidence from proxy-tracking services about lax verification policies, underscoring the widespread nature of this proxy network.

This new reporting from SecurityWeek provides further details on the NetNut takedown, highlighting that the network is believed to consist of over 2 million Android devices, including smart TVs and streaming boxes, infected via trojanized applications and malware like Badbox 2.0. It also specifies that the operator is linked to the publicly-traded Israeli firm Alarum Technologies Ltd, and that Google observed 316 distinct threat clusters using NetNut in a single week in June for malicious activities such as password-spray attacks.

The FBI and Google's operation not only targeted the NetNut infrastructure but also involved disabling Google accounts used for command-and-control and updating Google Play Protect to warn Android users and disable compromised apps. This coordinated effort significantly degraded the NetNut proxy network's operations and reduced its available device pool by millions, building upon previous disruptions like the IPIDEA proxy network takedown in January 2026.

This latest operation, involving Google, Lumen, Shadowserver, and the FBI, significantly degraded the NetNut residential proxy network, which is believed to have comprised over 2 million devices, primarily small TV-streaming hardware. The disruption is a continuation of efforts that previously targeted the IPIDEA proxy network and highlights the interconnected nature of these services, as NetNut also powered other proxy networks through its reseller program, suggesting further downstream effects.

The FBI's disruption of NetNut, a major residential proxy service, involved the seizure of multiple domain names and significantly degraded its operations, impacting over 2 million home devices. This action, supported by private sector partners including Google, Lumen Technologies, and the Shadowserver Foundation, directly targeted the infrastructure used by cybercriminals to mask malicious activities and cyberespionage campaigns.

This new report details a joint operation led by Google that has disrupted NetNut, a residential proxy service that leveraged millions of compromised Android devices, including smart TVs and streaming boxes. The operation effectively cut off access to these compromised endpoints, impacting the network's infrastructure and potentially affecting the scope of the FBI's earlier seizure of NetNut domains and the associated Popa botnet.

This new report from Malwarebytes Labs details the operational methods of the NetNut botnet, also known as Popa, and the specific technical levers used in its disruption by Google and the FBI. It elaborates on how devices were compromised, primarily through deceptive "bandwidth sharing" apps or pre-infected hardware, and highlights the use of Google Play Protect to remove malicious code from millions of devices. The article also provides actionable advice for users to avoid becoming part of future botnets.

Synthesized by Vypr AI