Cybersecurity & Privacy

FBI and Industry Partners Dismantle NetNut Residential Proxy Network, Disrupting Popa Botnet

The Federal Bureau of Investigation (FBI), in a significant operation conducted in collaboration with multiple industry partners, has successfully seized hundreds of internet domains associated with NetNut, a large-scale residential proxy service. NetNut is operated by Alarum Technologies, an Israeli company publicly traded on NASDAQ under the ticker ALAR. This decisive action follows closely on the heels of findings published by security researchers, which linked NetNut to the Popa botnet, an extensive network comprising at least two million compromised devices. The Popa botnet, according to these reports, has been surreptitiously activated on victims’ devices with minimal or no explicit consent.

The coordinated law enforcement and industry effort represents a major blow to the infrastructure used by cybercriminals to mask their malicious activities. The seizure notice, prominently displayed on NetNut’s homepage following the operation, underscores the gravity of the disruption. The FBI, in conjunction with the Internal Revenue Service Criminal Investigation division, acknowledged the critical assistance provided by companies such as Google, Lumen, and Shadowserver in dismantling the domains tied to the Popa botnet, a network long recognized as being intrinsically linked to NetNut’s residential proxy operations.

Unraveling the NetNut-Popa Connection

The intricate web connecting NetNut to the Popa botnet was brought to light on June 19, when three independent security firms released parallel findings. Their research revealed that NetNut functions as a residential proxy network that actively populates the Popa botnet. The service distributes software designed for devices commonly found in households, including smart televisions and streaming boxes. Once installed, NetNut’s software transforms these devices into always-on residential proxy nodes. These nodes are then rented out to third parties, who predominantly utilize them to relay illicit and intrusive internet traffic. Such traffic encompasses activities like mass content scraping, advertising fraud, and account takeover schemes, all of which inflict significant financial and operational damage on individuals and organizations.

The Google Threat Intelligence Group (GTIG) provided further depth to the understanding of NetNut’s operations in a blog post released concurrently with the FBI’s announcement. GTIG highlighted that NetNut’s proxy network is extensively resold and white-labeled by numerous third-party proxy providers. This widespread availability makes its services highly sought after by cybercriminals aiming to obscure the origins of their malicious activities. The GTIG’s observations revealed a significant scale of abuse; in a single week during June 2026, they identified 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes. These actors included sophisticated cybercriminal syndicates and espionage groups, underscoring the broad spectrum of malicious actors relying on the service.

Malicious Actors Leveraging NetNut for Obfuscation and Exploitation

The GTIG elaborated on the specific methods employed by malicious actors using NetNut. "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," the group stated in their report. This capability is crucial for attackers seeking to evade detection and attribution. Furthermore, the report detailed a more insidious consequence: "when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats." This highlights a critical vulnerability where innocent users’ home networks can become conduits for further cybercrime, potentially leading to the compromise of other connected devices.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Google’s involvement in the operation was multifaceted. The company confirmed that it disabled Google accounts and services that NetNut had been using for command and control of its malware infrastructure. Additionally, Google shared critical technical intelligence regarding NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement agencies, and research firms. The company also took action against applications known to bundle NetNut’s various SDKs, further limiting the service’s reach and operational capacity.

Corporate Responses and Legal Counsel

Omer Weiss, legal counsel representing NetNut’s parent company, Alarum Technologies, acknowledged awareness of the FBI’s seizure and confirmed the company’s cooperation with investigators. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated in a written release. This statement suggests a willingness from Alarum Technologies to distance itself from any illicit activities facilitated by its service, while also indicating a potential internal investigation into how its infrastructure may have been exploited.

Benjamin Brundage, founder of Synthient, a proxy tracking service that was among the firms publishing evidence linking the Popa botnet to NetNut and Alarum Technologies last month, provided an analysis of the operation’s impact. Brundage indicated that the domain seizures appear to have caused significant disruption to both the Popa botnet and the NetNut proxy network that underpins it.

Broader Implications for the Cybercrime Ecosystem

Brundage further suggested that the apparent demise of NetNut could present a substantial challenge for the cybercrime community. This is particularly relevant given that the community was already grappling with the aftermath of legal actions taken by Google earlier in the year, which resulted in the seizure of infrastructure belonging to NetNut’s primary competitor, IPIDEA. "I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage observed. He added that NetNut had become exceptionally common among resellers and was considered on par with IPIDEA in terms of daily traffic, quality, size, and pricing.

The disruption of NetNut and the Popa botnet may yield an additional benefit: a reduction in the effectiveness of large distributed denial-of-service (DDoS) botnets. These botnets have historically been constructed by exploiting poorly configured residential proxy services. Brundage referenced Synthient’s January revelation about the Kimwolf botnet, which was identified as the world’s largest DDoS botnet. Kimwolf had exploited IPIDEA proxy connections to gain access to the local networks of TV box owners, subsequently infecting other Android-based devices situated behind the victim’s firewall. While major proxy providers have taken steps to counteract such activities, resellers of these networks have been slower to adapt, allowing these threats to persist. "In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," Brundage stated.

The Fluidity of the Residential Proxy Market

Google, while acknowledging the significant degradation of NetNut’s proxy network and its business operations, reducing its available device pool by millions, issued a cautionary note. The company warned that proxy networks can reconstitute themselves by reselling other proxy services, a strategy observed with IPIDEA in recent months. "Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers." This suggests that law enforcement and cybersecurity firms must adopt a comprehensive strategy targeting the entire interconnected ecosystem of proxy services to achieve lasting disruption.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Consumer Vigilance: Protecting Devices from Proxy Software

The proliferation of residential proxy software on consumer devices, particularly smart TVs and streaming boxes, remains a significant concern. KrebsOnSecurity has previously highlighted that many low-cost TV streaming boxes sold on major e-commerce platforms either come pre-installed with residential proxy software or require the installation of proxy SDKs for essential functionality. This practice often goes unnoticed by consumers, who may unknowingly be contributing to botnets. Google’s advice to consumers is to prioritize reputable brands for TV boxes and to exercise caution when installing third-party applications. Consumers can verify if a device runs on the official Android TV OS with Play Protect certification by following specific instructions provided by Google.

The issue extends beyond TV boxes. Even individuals without dedicated streaming devices can find their smart televisions enrolled in residential proxy networks through applications available on platforms like Samsung and LG smart TVs. A recent report by Spur found that a significant percentage of apps for LG’s webOS and Samsung’s Tizen operating systems included SDKs that transform televisions into always-on residential proxy nodes. This pervasive integration of proxy functionality into seemingly innocuous applications underscores the need for increased consumer awareness and due diligence.

Financial Repercussions and Future Outlook

The ramifications of the FBI’s action have extended to Alarum Technologies’ financial standing. Following the FBI’s operation, the company’s stock experienced a significant decline, reportedly trading at $2.62 per share, representing a roughly 67 percent decrease over the past week. The website for Alarum Technologies, alarum[.]io, now also displays a seizure notice from the FBI, further cementing the impact of the law enforcement action.

The coordinated takedown of NetNut and the Popa botnet marks a significant victory in the ongoing battle against cybercrime. However, as Google’s analysis suggests, the dynamic nature of the residential proxy market necessitates continuous vigilance and adaptive strategies from law enforcement and cybersecurity professionals. The ability of these networks to pivot and reshare capacity means that a holistic approach targeting interconnected providers will be crucial for achieving sustained disruption. For consumers, the message is clear: understanding the software running on their devices and exercising caution with app installations are essential steps in safeguarding their personal networks from becoming unwitting participants in criminal activities.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Snapost
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.