Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [le-action, cybercrime-group, c2, incident] ยท confidence: high ยท affected_sectors: [technology, government, defence] ยท au_impact: true

NetNut / Popa Botnet Takedown

In a major law enforcement operation, the FBI seized hundreds of domains associated with NetNut, a residential proxy service operated by the Israeli company Alarum Technologies (NASDAQ: ALAR), along with the Popa botnet โ€” a network of at least 2 million compromised devices.

Timeline

Date Event
July 2, 2026 FBI seizure of hundreds of domains
July 7, 2026 Details published by Krebs on Security
Ongoing Google disables related accounts and apps

The Operation

  • FBI led the takedown in coordination with Google, Lumen Technologies, and Shadowserver Foundation
  • Hundreds of domains seized
  • Google observed 316 distinct threat-actor clusters using NetNut exit nodes in a single week (raw/digests/Cyber-Digest-2026-07-07)

NetNut's Business Model

NetNut provided a residential proxy service that allowed customers to route traffic through end-user devices whose owners were unaware of the proxying. NetNut's SDKs were widely bundled in consumer applications, including smart TVs and streaming boxes.

Popa Botnet

  • At least 2 million compromised devices
  • Included smart TVs and streaming boxes
  • Used to relay abusive traffic (credential stuffing, advertising fraud, account takeover)
  • Some devices were bundled with NetNut SDKs that proxied traffic without user consent (raw/digests/Cyber-Digest-2026-07-09)

Impact

  • 316 threat-actor clusters lost their proxy infrastructure
  • Google disabled accounts and apps associated with the NetNut SDK
  • One of the most significant takedowns of a proxy-based cybercrime-enablement service

Australian Angle

NetNut SDKs were globally distributed. Australian organisations using consumer applications that bundled NetNut should audit their software supply chain. The takedown demonstrates the effectiveness of FBI-led international cyber operations โ€” relevant to Afp and Acsc operational planning. Au Impact

Related Pages

  • Scattered Spider โ€” Another significant LE action (guilty pleas)
  • Lurking Lizard โ€” Similar residential proxy operation (smaller scale)
  • Uat 7810 โ€” Compromised-device relay network (different threat actor)