Popa Botnet / NetNut Residential Proxy Network
First seen Jul 4, 2026 · Updated Jul 4, 2026
The FBI, working with industry partners, seized hundreds of domains linked to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The takedown follows security research connecting NetNut to the Popa botnet, a network of at least two million devices compromised without meaningful user consent. This represents a significant disruption to a large-scale proxyware/botnet infrastructure used to monetize unwitting victims' internet connections.
Technical Analysis
The Popa botnet reportedly compromises devices via bundled software, SDKs, or malicious applications that silently enroll victim devices as exit nodes in a residential proxy network, enabling traffic anonymization for paying customers of NetNut. No specific CVEs were disclosed in the source reporting, suggesting infection likely occurs through deceptive bundling, third-party app SDKs, or free VPN/software installers rather than exploitation of a software vulnerability. The scale (2M+ devices) indicates a mature distribution pipeline, likely leveraging affiliate monetization schemes common in proxyware ecosystems. The FBI seizure targeted hundreds of domains supporting NetNut's infrastructure, disrupting command, provisioning, and proxy-routing capabilities. Further technical indicators (specific malware families, C2 protocols, hashes) were not provided in available reporting.
Affected Systems
Consumer and possibly enterprise endpoints (Windows, macOS, Android, IoT devices) running bundled proxyware/SDK components; systems with free VPN, ad-supported, or cracked software installed that silently enrolled devices into the residential proxy network.
Indicators of Compromise
- Domain: netnut[.]io (and hundreds of associated seized domains - full list not published in source)
- Associated entity: Alarum Technologies Ltd. (NASDAQ: ALAR)
- Botnet name: Popa
Remediation Steps
- 1
Audit installed software
Review systems for unauthorized proxyware, free VPN clients, or bundled SDKs that may enroll devices as network exit nodes.
- 2
Network egress monitoring
Monitor outbound traffic for connections to known NetNut infrastructure and residential proxy relay behavior.
- 3
Remove unauthorized proxy agents
Uninstall any identified proxyware clients or SDK-bundled applications; scan with updated endpoint protection to remove residual components.
- 4
User awareness training
Educate users on risks of installing free/cracked software and ad-supported apps that monetize device bandwidth without clear consent.
- 5
Threat intel integration
Ingest updated domain/IP indicators from law enforcement and security vendor disclosures as they become available to block related infrastructure.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.