LIVE · cybersecurity feed
Live wire
malware

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo

zeroday.news · 30d ago

The Federal Bureau of Investigation, in collaboration with industry partners, has seized hundreds of domains associated with NetNut, a large residential proxy service operated by the Israeli company Alarum Technologies. This action follows recent reports from security firms that linked NetNut to the Popa botnet, a network of at least two million compromised devices.

The FBI's seizure notice, which replaced NetNut's homepage, indicated the involvement of the Internal Revenue Service Criminal Investigation division. The notice also acknowledged contributions from Google, Lumen, Shadowserver, and other industry partners in dismantling the domains tied to the Popa botnet, which is closely associated with NetNut's proxy infrastructure.

Security researchers had previously identified NetNut as a residential proxy network that populates the Popa botnet. The service distributes software that transforms everyday home devices, such as smart TVs and streaming boxes, into always-on proxy nodes. These nodes are then rented out to individuals who predominantly use them for illicit online activities, including mass content scraping, advertising fraud, and account takeovers.

Google's Threat Intelligence Group (GTIG) noted that NetNut's proxy network is widely resold and white-labeled by various third-party providers. Cybercriminals frequently utilize NetNut's services to conceal the origin of their malicious traffic. GTIG observed a significant number of threat actor groups, including those involved in cybercrime and espionage, leveraging NetNut exit nodes within a single week in June 2026. These actors use NetNut to mask their IP addresses when accessing victim environments, their own infrastructure, or conducting password spray attacks.

Furthermore, when consumer devices become proxy exit nodes, unauthorized network traffic can pass through them. This exposes other private devices on the same home network to potential internet threats. Google stated that it disabled Google accounts and services used by NetNut for command and control of malware and shared technical intelligence about NetNut's software development kits and backend infrastructure with relevant parties. The company also disabled applications known to bundle NetNut's SDKs.

Omer Weiss, legal counsel for NetNut's parent company Alarum Technologies, confirmed awareness of the FBI seizure and stated the company is cooperating with investigators. Weiss emphasized the company's commitment to a thorough investigation of any misuse of its infrastructure.

Benjamin Brundage, founder of the proxy tracking service Synthient, one of the firms that published evidence linking the Popa botnet to NetNut, suggested that the domain seizures have significantly disrupted both the Popa botnet and NetNut's proxy network. Brundage believes this takedown will be a considerable blow to the cybercrime community, especially following earlier legal actions by Google against NetNut's main competitor, IPIDEA. He noted that NetNut had gained substantial popularity after the IPIDEA takedown and was comparable to IPIDEA in terms of traffic, quality, size, and pricing.

Brundage also suggested that the disruption of NetNut and the Popa botnet could help mitigate the impact of large distributed denial-of-service botnets that exploit poorly configured residential proxy services. He referenced a previous Synthient report detailing how cybercriminals built a large DDoS botnet by tunneling through IPIDEA proxy connections into the local networks of TV box owners. While major proxy providers have taken steps to block such activity, resellers have been slower to respond.

Google estimates that the recent actions have severely degraded NetNut's proxy network and business operations, reducing the available pool of devices by millions. However, Google cautions that proxy networks can reconstitute themselves by reselling services from other providers, as IPIDEA has reportedly done. Google indicated that many popular residential proxy brands may be white-labeling the NetNut botnet and anticipates that while this disruption will have a broad impact, individual networks can prove resilient. The company observed that when faced with botnet degradation, proxy operators often purchase capacity from competitors, effectively becoming resellers. Google believes that to achieve lasting disruption in this dynamic ecosystem, efforts must target the infrastructure of multiple interconnected providers.

The report also highlighted concerns about smart TVs and streaming devices, noting that many low-cost streaming boxes sold online come pre-installed with residential proxy software or require users to install proxy SDKs. Google advises consumers to purchase devices from reputable manufacturers and exercise caution with installed applications. Devices compromised by the Popa botnet and similar threats often use unofficial Android operating systems that lack Google Play Protect certification.

Consumers can verify if a device runs an official Android TV OS with Play Protect certification by following specific instructions. Additionally, smart TVs from manufacturers like Samsung and LG can become part of residential proxy networks through the installation of third-party applications. A recent report found that a significant percentage of apps available for LG's webOS and Samsung's Tizen operating systems contain SDKs that turn televisions into residential proxy nodes.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.