Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

FBI Seizes NetNut Proxy Network Linked to Popa Botnet, Shutting Down Millions of Devices

DECRYPTED BY: Nova Stirling | TIMESTAMP: 2026-07-04 T 20:39:16 Z | [ 2 MIN READ ]
FBI Seizes NetNut Proxy Network Linked to Popa Botnet, Shutting Down Millions of Devices
2 Min Read
Share

The Federal Bureau of Investigation announced today, in coordination with industry partners, the seizure of more than ↓ 300 domains that powered the NetNut proxy service operated by Israeli‑listed Alarum Technologies (NASDAQ:ALAR).

NetNut proxy Tied to Popa Botnet of ↓ 2 million Compromised Devices

Security researchers from KrebsOnSecurity, Google Threat Intelligence Group and independent firms converged in mid‑June to link the residential‑proxy platform to the Popa botnet, a network of at least two million smart TVs, streaming boxes and other IoT gadgets infected without user consent.

The botnet converts these home devices into always‑on exit nodes that criminals rent to hide malicious traffic, fuel mass content scraping, advertising fraud and account‑takeover campaigns.

“Alarum takes this matter seriously and will fully cooperate with law enforcement,” said Omer Weiss, legal counsel for the NetNut parent, in a written statement.

Google’s GTIG reported observing 316 distinct threat‑actor clusters leveraging suspected NetNut exit nodes in a single week, ranging from cyber‑crime groups to state‑linked espionage units. The firm also disabled Google accounts used for command‑and‑control and removed apps bundling NetNut SDKs.

Industry allies including Reuters and Bloomberg were thanked for assistance in dismantling the infrastructure, which experts say will cripple the cyber‑crime ecosystem that surged after the earlier takedown of rival IPIDEA.

Analysts predict a short‑term shock to the residential‑proxy market, but warn that resilient operators may re‑brand or purchase capacity from competitors, keeping the threat alive.


Analysis by Nova Stirling (Aerospace & Space Tech Correspondent).

Global Data Feed

More from this Intel

Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Zero‑Day WordPress Core Flaw Exposes Sites to Unauthenticated Code Execution

Jul 19, 2026
Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software Exploits

Capital One Unveils VulnHunter: Open‑Source AI Tool to Preempt Software...

Jul 18, 2026
Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written Rules

Brex Reinvents AI Agent Policy with Network‑Level Enforcement, Not Pre‑Written...

Jul 18, 2026
SonicWall SMA zero-day exploited by Inc ransomware

SonicWall SMA zero-day exploited by Inc ransomware

Jul 18, 2026
Brian Chesky X Hack Exposes AI‑Generated Crypto Spam on CEO’s Account

Brian Chesky X Hack Exposes AI‑Generated Crypto Spam on CEO’s...

Jul 17, 2026
Secure Boot Blind Spot: Forgotten Bootloaders Leave Systems Exposed

Secure Boot Blind Spot: Forgotten Bootloaders Leave Systems Exposed

Jul 16, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.