{"id":61944,"date":"2026-07-03T14:48:33","date_gmt":"2026-07-03T18:48:33","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=61944"},"modified":"2026-07-03T14:48:33","modified_gmt":"2026-07-03T18:48:33","slug":"fbi-seizes-netnut-popabotnet","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/fbi-seizes-netnut-popabotnet\/","title":{"rendered":"FBI Seizes NetNut Proxy Platform, Popa Botnet"},"content":{"rendered":"<p>The Federal Bureau of Investigation (FBI), in coordination with the Internal Revenue Service Criminal Investigation division and industry partners including Google, Lumen, and Shadowserver, has seized hundreds of domains tied to NetNut, a residential proxy network operated by the publicly traded Israeli company <a href=\"https:\/\/www.alarum.com\/\" target=\"_blank\" rel=\"sponsored noopener noreferrer\" data-iacss-external=\"1\">Alarum Technologies<\/a> (NASDAQ: ALAR). The action, which replaces NetNut&#8217;s homepage with a federal seizure notice, follows the discovery by three independent security firms that NetNut&#8217;s infrastructure is synonymous with the Popa botnet, a sprawling network of at least two million compromised consumer devices.<\/p>\n<h2>What Is NetNut and How Does the Popa Botnet Operate?<\/h2>\n<p>NetNut is a residential proxy service that uses software installed on everyday consumer devices, such as smart televisions and Android-based streaming boxes, to turn them into always-on proxy nodes. These nodes are then rented to customers who use them to route internet traffic through the compromised devices, effectively masking the original source of that traffic. Security researchers from multiple firms concluded that the software NetNut distributes populates a botnet known as Popa, which has been linked to mass content scraping, advertising fraud, credential-stuffing attacks, and account takeover campaigns. Victims generally do not consent to their devices being enrolled in this proxy network, as the software is either pre-installed on low-cost streaming boxes or bundled into applications downloaded from third-party stores.<\/p>\n<h2>The Takedown: Law Enforcement and Industry Partners Act<\/h2>\n<p>On July 2, the FBI seized hundreds of domains associated with both NetNut and the Popa botnet. The seizure banner now displayed on the NetNut homepage explicitly acknowledges the involvement of Google, Lumen, and the Shadowserver Foundation in dismantling the infrastructure. Omer Weiss, legal counsel for Alarum Technologies, confirmed the company is aware of the seizure and stated it would &#8220;fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.&#8221; Google&#8217;s Threat Intelligence Group (GTIG) reported that in a single week during <a href=\"https:\/\/overcentral.com\/en\/roblox-duel-warriors-gets-new-working-codes-for-june-2026\/\" title=\"Roblox Duel Warriors Gets New Working Codes for June 2026\" data-iacss-internal=\"1\">June 2026<\/a>, it identified 316 distinct clusters of threat actors using suspected NetNut exit nodes, including groups engaged in cybercrime and espionage. Google has disabled accounts and services used by NetNut for malware command and control, disabled apps bundling NetNut&#8217;s software development kits, and shared technical intelligence with platform providers and research firms.<\/p>\n<h2>What Is a Residential Proxy Network and Why Is It Dangerous?<\/h2>\n<p>A residential proxy network routes internet traffic through real consumer devices located in homes, making the traffic appear to originate from legitimate residential IP addresses. This technique is heavily exploited by cybercriminals to bypass geo-restrictions, evade detection by security systems, and obscure the source of malicious activity. Google&#8217;s GTIG warned that when a consumer device becomes an exit node, unauthorized network traffic passes through it, potentially giving attackers access to other private devices on the same home network and exposing them to internet-borne threats. The danger extends beyond privacy invasion; compromised devices can be used as launching pads for distributed denial-of-service (DDoS) attacks, credential theft, and other intrusive operations.<\/p>\n<h2>Impact on the Cybercrime Ecosystem<\/h2>\n<p>Benjamin Brundage, founder of the proxy tracking service Synthient, described the takedown as a significant disruption. The Popa botnet and the <a href=\"https:\/\/overcentral.com\/en\/google-disrupts-netnut-proxy-network\/\" title=\"Google Disrupts NetNut Proxy Network Spanning 2 Million Home Devices\" data-iacss-internal=\"1\">NetNut proxy network<\/a> that relies on it have both been severely impacted. Brundage noted that NetNut had gained substantial popularity after a previous legal action by Google disabled its largest competitor, IPIDEA, earlier this year. &#8220;I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown,&#8221; he said. &#8220;Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.&#8221; He also suggested that disrupting NetNut could lessen the impact of large DDoS botnets, such as Kimwolf, which were built by tunneling through residential proxy connections into the local networks of TV box owners.<\/p>\n<p>Google acknowledged that proxy networks can rebuild by reselling capacity from competitors, as IPIDEA has done. &#8220;Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,&#8221; the GTIG report states. &#8220;While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient.&#8221; The company warned that creating a lasting disruption will require targeting the infrastructure of several interconnected providers simultaneously.<\/p>\n<h2>Consumer Risk: Smart TVs and Streaming Boxes Remain a Vector<\/h2>\n<p>The devices most commonly co-opted by the Popa botnet are low-cost Android TV streaming boxes, often sold through major e-commerce platforms without official Play Protect certification. These devices either come pre-installed with proxy software or require users to install it to access pirated streaming content. However, the threat is not limited to these devices. Research from the tracking firm Spur found that 42 percent of apps available for download on LG&#8217;s webOS operating system include software development kits that turn a television into an always-on proxy node. More than a quarter of apps made for Samsung&#8217;s Tizen operating system contain similar components. Even users who do not own a streaming box may find their smart TV enrolled in a proxy network simply by installing certain apps from official app stores.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Anyone who owns a no-name Android TV streaming box or has installed third-party apps on a smart TV from LG or Samsung should take immediate steps to verify their device&#8217;s integrity. Change all passwords associated with accounts accessed from that device, enable two-factor authentication wherever possible, and monitor financial accounts for signs of fraud or unauthorized activity. For streaming boxes running unofficial Android operating systems, the safest course of action is to disconnect them from your network entirely and replace them with a device that carries official Play Protect certification, which can be verified through Google&#8217;s support instructions. For smart TVs, review all installed applications and remove any that are not from a trusted, well-known publisher. In addition, using a reputable no-log <a href=\"https:\/\/overcentral.com\/en\/bypass-grindr-ban-vpn-reset\/\" title=\"Grindr Users Bypass Bans with VPNs and Device Resets\" data-iacss-internal=\"1\">VPN<\/a> with a verified no-logs policy and a kill switch adds a critical layer of protection when accessing the internet from any connected device, as it helps ensure that your traffic cannot be intercepted or rerouted by malicious nodes on your home network. Finally, consider investing in a multi-layer endpoint protection solution capable of detecting and blocking unauthorized outbound connections, which can help identify whether a device on your network has been enrolled in a residential proxy scheme without your consent.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Federal Bureau of Investigation (FBI), in coordination with the Internal Revenue Service Criminal Investigation division and industry partners including Google, Lumen, and Shadowserver, has seized hundreds of domains tied to NetNut, a residential proxy network operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). The action, which replaces NetNut&#8217;s homepage with a [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84213,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/61944.png","fifu_image_alt":"FBI Seizes NetNut Proxy Platform, Popa Botnet","footnotes":""},"categories":[349],"tags":[],"class_list":["post-61944","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/61944.png","fifu_image_alt":"FBI Seizes NetNut Proxy Platform, Popa Botnet","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/61944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=61944"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/61944\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84213"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=61944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=61944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=61944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}