Cybersecurity and Digital Privacy

FBI Seizes Hundreds of Domains Linked to NetNut Residential Proxy Service, Disrupting Popa Botnet

The Federal Bureau of Investigation (FBI), in a significant coordinated action with industry partners, announced today the seizure of hundreds of internet domains associated with NetNut, a large-scale residential proxy service operated by the publicly-traded Israeli company Alarum Technologies (NASDAQ: ALAR). This decisive move follows a series of revelations approximately two weeks prior, where multiple cybersecurity firms connected NetNut to the Popa botnet, a vast network comprising at least two million compromised devices. The victims of this compromise often had little to no knowledge of their devices being enlisted in this illicit operation.

Genesis of the Operation: Popa Botnet and NetNut’s Role

The entanglement of NetNut with malicious activities came to light on June 19th, when three independent cybersecurity firms released strikingly similar findings. Their reports detailed how NetNut functioned as a residential proxy network that actively populated the Popa botnet. The service was found to distribute software for common household devices, including smart televisions and streaming boxes. Upon installation, NetNut’s software transforms these devices into perpetually active residential proxy nodes. These nodes are then rented out to third parties who primarily utilize them for relaying abusive and intrusive internet traffic. This traffic is frequently associated with large-scale content scraping, advertising fraud schemes, and account takeover attacks, underscoring the pervasive and detrimental impact of such networks.

The Seizure and Its Immediate Aftermath

The culmination of these investigations and law enforcement efforts was dramatically illustrated earlier today when the NetNut homepage was replaced by a prominent seizure banner from the FBI and the Internal Revenue Service Criminal Investigation division. This visual declaration of law enforcement action was accompanied by acknowledgments of crucial support from industry collaborators, including Google, Lumen, Shadowserver, and other partners who played vital roles in dismantling the extensive network of domains tied to the Popa botnet. For years, cybersecurity experts have recognized the Popa botnet as being intrinsically linked to NetNut’s residential proxy infrastructure, making this seizure a direct blow to both entities.

Google’s Perspective: Obfuscation and Exploitation

The Google Threat Intelligence Group (GTIG) provided further context in a blog post published today, elaborating on NetNut’s widespread use by malicious actors. The GTIG highlighted that NetNut’s proxy network is extensively resold and often white-labeled by numerous third-party proxy providers. This accessibility makes its services highly attractive to cybercriminals seeking to mask the origin of their illicit online activities. According to GTIG’s observations, in a single week during June 2026, they identified 316 distinct clusters of threat actors leveraging suspected NetNut exit nodes. These actors spanned a spectrum from common cybercriminal groups to sophisticated espionage organizations.

"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google’s GTIG stated in their official blog. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."

Google’s involvement was not merely observational. The tech giant confirmed that it had disabled Google accounts and services that were being utilized by NetNut for command and control of malware. Furthermore, Google proactively shared critical technical intelligence concerning NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement agencies, and research firms. In addition to these measures, Google also disabled applications that were known to bundle various NetNut SDKs, further disrupting their operational capabilities.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Company Response and Expert Analysis

Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, acknowledged the FBI’s seizure and affirmed the company’s commitment to cooperating with the ongoing investigation. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated in a written declaration.

Benjamin Brundage, founder of Synthient, a proxy tracking service, and one of the firms that published evidence linking the Popa botnet to NetNut and Alarum Technologies last month, offered his expert analysis. Brundage suggested that the domain seizures have indeed disrupted both the Popa botnet and the NetNut proxy network operating above it. He posited that the apparent demise of NetNut represents a significant setback for the cybercrime community, which was already grappling with the repercussions of legal actions taken by Google earlier this year against IPIDEA, NetNut’s primary competitor.

"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage commented. "Also, NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."

Broader Implications for Cybersecurity and Distributed Denial-of-Service Attacks

Brundage further suggested that the successful disruption of NetNut and the Popa botnet could have a secondary, yet significant, benefit: mitigating the impact of large-scale distributed denial-of-service (DDoS) botnets. These botnets have frequently been built upon the foundation of poorly secured residential proxy services. He referenced Synthient’s earlier revelation in January concerning the Kimwolf botnet, identified as the world’s largest DDoS botnet. Kimwolf exploited residential proxy connections, such as those provided by IPIDEA, to tunnel into the local networks of TV box owners, subsequently infecting other Android-based devices residing behind the victim’s firewall.

While many of the larger, more reputable proxy providers have taken steps to prevent such malicious activities, Brundage noted that resellers of these major proxy networks have been notably slower to address the emerging threats. "In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," he stated, indicating a positive ripple effect for overall internet security.

Google’s GTIG echoed this sentiment, estimating that the actions taken today have caused "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." However, the GTIG also cautioned that proxy networks possess a degree of resilience, capable of reconstituting themselves by reselling services from other providers, a strategy observed with IPIDEA in recent months.

"Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Pervasive Threat of Pre-Installed Proxy Software on Consumer Devices

The issue of residential proxy software being embedded in consumer devices remains a significant concern for cybersecurity experts and users alike. As KrebsOnSecurity has repeatedly warned, many unbranded TV streaming boxes available on major e-commerce platforms either come pre-installed with residential proxy software or require users to install proxy SDKs to enable basic functionality. This is often tied to the use of these devices for accessing pirated content. Google’s advice to consumers is to prioritize reputable brands from established manufacturers and to exercise caution when installing any applications on these devices.

Devices that are compromised by the Popa botnet and similar threats are often found to be running unofficial Android operating systems that do not adhere to Google’s Play Protect certification standards. Consumers can verify the authenticity of their Android TV OS and Play Protect certification by following Google’s official guidelines.

The problem extends beyond TV boxes. Even individuals who do not own dedicated streaming devices can find their smart televisions inadvertently enrolled in residential proxy networks. This can occur through the installation of applications available on platforms like Samsung and LG smart TVs. A report released last month by Spur, a proxy tracking company, found that a significant percentage of apps available for LG’s webOS operating system (42%) included SDKs that transform the television into a residential proxy node. Similarly, more than a quarter of apps developed for Samsung’s Tizen operating system were found to contain comparable residential proxy components.

A Ripple Effect and Future Challenges

The takedown of NetNut and the Popa botnet represents a significant victory in the ongoing battle against cybercrime. However, the dynamic nature of the residential proxy ecosystem suggests that new players or repurposed services may emerge to fill the void. The reliance on white-labeling and reselling among proxy providers means that disruptions to one major network can lead to a redistribution of traffic and resources across others.

The FBI’s action, bolstered by the collaboration of tech giants like Google and specialized security firms, demonstrates a growing commitment to tackling these complex, multi-faceted threats. The financial repercussions for Alarum Technologies have been swift and severe, with its stock experiencing a substantial decline following the FBI’s announcement. As of a recent update, the company’s stock was trading at a significantly reduced value, reflecting market reaction to the law enforcement action. The ongoing investigation and the potential for further legal actions underscore the serious consequences for entities involved in facilitating illicit online activities.

The long-term impact of this seizure will depend on the ability of law enforcement and cybersecurity researchers to maintain vigilance and adapt to the evolving tactics of cybercriminals. The interconnectedness of the proxy market means that sustained disruption will likely require ongoing, coordinated efforts targeting multiple interconnected providers, as Google has indicated. The fight to secure the internet, particularly concerning the exploitation of everyday consumer devices, remains a complex and evolving challenge.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button