NetNut / Popa Botnet Takedown
In a major law enforcement operation, the FBI seized hundreds of domains associated with NetNut, a residential proxy service operated by the Israeli company Alarum Technologies (NASDAQ: ALAR), along with the Popa botnet โ a network of at least 2 million compromised devices.
Timeline
| Date | Event |
|---|---|
| July 2, 2026 | FBI seizure of hundreds of domains |
| July 7, 2026 | Details published by Krebs on Security |
| Ongoing | Google disables related accounts and apps |
The Operation
- FBI led the takedown in coordination with Google, Lumen Technologies, and Shadowserver Foundation
- Hundreds of domains seized
- Google observed 316 distinct threat-actor clusters using NetNut exit nodes in a single week (raw/digests/Cyber-Digest-2026-07-07)
NetNut's Business Model
NetNut provided a residential proxy service that allowed customers to route traffic through end-user devices whose owners were unaware of the proxying. NetNut's SDKs were widely bundled in consumer applications, including smart TVs and streaming boxes.
Popa Botnet
- At least 2 million compromised devices
- Included smart TVs and streaming boxes
- Used to relay abusive traffic (credential stuffing, advertising fraud, account takeover)
- Some devices were bundled with NetNut SDKs that proxied traffic without user consent (raw/digests/Cyber-Digest-2026-07-09)
Impact
- 316 threat-actor clusters lost their proxy infrastructure
- Google disabled accounts and apps associated with the NetNut SDK
- One of the most significant takedowns of a proxy-based cybercrime-enablement service
Australian Angle
NetNut SDKs were globally distributed. Australian organisations using consumer applications that bundled NetNut should audit their software supply chain. The takedown demonstrates the effectiveness of FBI-led international cyber operations โ relevant to Afp and Acsc operational planning. Au Impact
Related Pages
- Scattered Spider โ Another significant LE action (guilty pleas)
- Lurking Lizard โ Similar residential proxy operation (smaller scale)
- Uat 7810 โ Compromised-device relay network (different threat actor)