FBI Dismantles NetNut Proxy and Popa Botnet Operations

The FBI has seized hundreds of NetNut domains in a joint operation with Google, Lumen and Shadowserver, disrupting a residential proxy service tied to over two million compromised devices.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: FBI agents in a server room, with racks of servers and computer screens displaying FBI seizure notices
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The FBI seized hundreds of domains linked to NetNut, a residential proxy service run by Alarum Technologies.
  • Three security firms connected NetNut to the Popa botnet on 19 June, compromising at least two million devices.
  • In one week during June 2026, Google's Threat Intelligence Group tracked 316 distinct threat-actor clusters using NetNut exit nodes.
  • The seizure disrupted both the Popa botnet and NetNut's proxy network, and may reduce the reach of large DDoS botnets.
  • Google warns that proxy networks can rebuild by reselling capacity from competitors, as IPIDEA did after its own takedown.

The FBI, alongside the IRS Criminal Investigation division, has seized hundreds of domains tied to NetNut, a residential proxy service run by publicly traded Israeli company Alarum Technologies. NetNut's homepage was replaced by a seizure notice crediting Google, Lumen and Shadowserver as partners. We've been tracking NetNut since 18 June, and our 2 July story "Google and FBI Kneecap NetNut, Cutting Millions of Home Devices From Proxy Pool" first reported the joint operation stripping millions of infected devices from the proxy pool.

The Popa botnet, flagged by three security firms on 19 June, installs software on home devices, particularly Android-based smart TVs and streaming boxes, turning them into always-on proxy nodes. Those nodes are then rented out, mainly to relay content scraping, advertising fraud and account-takeover traffic. Alarum disputed the botnet characterisation before the seizure and threatened legal action against outlets that published the findings.

Google's Threat Intelligence Group (GTIG) said NetNut's proxy network is widely resold and white-labeled by third-party providers. In a single week during June 2026, GTIG counted 316 distinct clusters of threat actors, including cybercriminal and espionage groups, using suspected NetNut exit nodes. "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," GTIG wrote. When a consumer device becomes an exit node, the group warned, other devices on the same home network are exposed to threats from outside.

Google disabled accounts and apps that bundled NetNut's software development kits (SDKs), shared technical intelligence with law enforcement and research firms, and says the action caused "significant degradation to NetNut's proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions."

Benjamin Brundage, founder of proxy-tracking service Synthient, one of the firms that published evidence linking Popa to NetNut, told KrebsOnSecurity the domain seizures have disrupted both layers of the operation. NetNut's collapse hits the cybercrime community twice over: it had already gained users after Google's earlier legal action against IPIDEA, NetNut's biggest competitor, and was reportedly on par with IPIDEA for daily traffic, quality and price per gigabyte. Brundage also said the takedown should reduce the reach of large DDoS botnets, because criminals had been tunnelling through residential proxy connections to infect other Android devices on victims' home networks.

The resilience problem is real, though. IPIDEA rebuilt after its own disruption by buying capacity from competitors, and GTIG says the same playbook is available to anyone who survives a takedown. "Creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers," the group concluded.

How can defenders mitigate risks from compromised devices?

For smart TVs and streaming boxes, the answer is straightforward: buy name-brand hardware from reputable manufacturers, and be selective about every app you install. The devices being pulled into botnets like Popa all run unofficial Android operating systems that sit outside Google's Play Protect programme. Home users can't easily detect proxy SDKs themselves, so the real defence is prevention: don't buy the sketchy $40 box in the first place.

© 2026 Threat Vectr