FBI and Partners Dismantle NetNut Proxy Network and Popa Botnet
Malware

Illustrative image generated with AI

FBI and Partners Dismantle NetNut Proxy Network and Popa Botnet

FBI and partners seized hundreds of NetNut proxy domains and dismantled the Popa botnet, disrupting a massive white-label criminal proxy ecosystem.

Text generated by artificial intelligence, published without human review. AI transparency

Introduction

A joint operation led by the FBI and the Internal Revenue Service – Criminal Investigation, with support from Google, Lumen, Shadowserver, and other industry partners, has resulted in the seizure of hundreds of domains belonging to NetNut, a residential proxy platform operated by Israeli company Alarum Technologies (NASDAQ: ALAR). Concurrently, the Popa botnet was dismantled — a vast infrastructure of compromised home devices (at least two million smart TVs and streaming boxes) that powered the service's exit nodes. The action disrupts a “white label” criminal ecosystem exploited by espionage groups and cybercriminals to anonymize illicit traffic, but the platform’s very nature suggests that the ecosystem’s resilience will require iterative actions.

Technical Analysis

NetNut operated as a “legitimate” residential proxy service by selling access to home IP addresses to third-party clients. However, investigations revealed that its infrastructure was built on the Popa botnet — devices infected without user consent. Compromised nodes were enrolled through malicious software (often delivered via smart TV or Android box applications containing hostile SDKs) and managed as exit points for paying customers’ traffic.

The technical operation involved:

  • Seizure of the platform’s control and management domains by authorities.
  • Disabling by Google of accounts and cloud services used as command and control (C2) channels, and removal of applications containing malicious SDKs from the Play Store and other ecosystems.
  • Intelligence sharing by Google Threat Intelligence Group (GTIG): in a single week of monitoring, 316 distinct clusters of malicious actors — including espionage groups and common criminals — were observed using NetNut nodes for mass scraping, ad fraud, account takeover, and password spraying.
  • Collaboration with Lumen (Black Lotus Labs), Shadowserver, and Synthient, which contributed tracking data and analysis of proxy networks.

The action follows the previous takedown of competitor IPIDEA, previously targeted by Google; NetNut had quickly inherited that portion of criminal clientele, demonstrating the fluidity of the malicious residential proxy market. Alarum Technologies stated full cooperation with investigators.

Impact

The immediate degradation of NetNut’s operational capability is significant: millions of exit nodes have become unavailable, creating a cascading effect on numerous “white label” resellers that purchased access to the platform to offer anonymization services.

On the criminal front, the impact includes:

  • Disruption of active malicious campaigns that used the proxies for reconnaissance, credential theft, and propagation of DDoS botnets (e.g., Kimwolf) via lateral movement within exposed home networks.
  • Loss of trust in an ecosystem already shaken by the fall of IPIDEA.

However, the resilience of the “white label” model is well-known: surviving providers can capture the clientele by expanding their own capacity, making a coordinated and repeated approach against multiple interconnected platforms essential for lasting impact.

Mitigation

The operation relies on an integrated countermeasure model combining legal, technical, and intelligence actions:

  • Legal action and seizures: FBI and IRS-CI obtained authority to seize domains, disrupting infrastructure control.
  • Cloud service disabling and app removal: Google disabled accounts linked to C2 activities and removed applications with malicious SDKs, hitting the infection cycle.
  • Sharing of indicators of compromise (IOCs): details on domains, IPs, SDK fingerprints, and C2 mechanisms were distributed to platforms, providers, and researchers, enabling proactive blocking.
  • Recommendations for enterprises:
    • Block traffic from known and suspicious residential proxy IP ranges.
    • Enforce multi-factor authentication (MFA) to counter credential stuffing.
    • Monitor access logs for signs of password spraying and account takeover.
  • Long-term strategy: cyclically dismantle the infrastructures of multiple interconnected providers (not limited to a single target) to undermine the malicious proxy ecosystem’s ability to regenerate.

FAQ

1. What is the Popa botnet and how did it work?
Popa was a botnet composed of at least 2 million home devices – mainly smart TVs and Android-based streaming boxes – infected via malicious applications containing hostile SDKs. Devices were turned into residential proxies, routing third-party traffic through home connections unbeknownst to the owners, exposing the entire home network to risks.

2. How did the FBI manage to dismantle the NetNut platform?
The FBI, with support from industry partners such as Google, seized hundreds of domains used to run the platform. Concurrently, Google disabled accounts and cloud services that served as command and control centers and removed the applications that delivered the infection. Shared intelligence enabled simultaneous targeting of multiple infrastructure points.

3. Can personal devices still be infected? And how to protect them?
Yes, if users installed apps from unofficial sources or do not verify requested permissions, the device may still be compromised. It is advisable to remove suspicious applications, factory reset devices when in doubt, and install software only from official stores. For enterprises, it is crucial to block connections to IPs belonging to known residential proxies and enforce MFA on all accounts.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsNetNut proxy networkPopa botnetFBI cyber takedownresidential proxycybercrime disruptionAlarum Technologies
Back to home