highMalware

Popa Botnet / NetNut Residential Proxy Network

First seen Jul 4, 2026 · Updated Jul 4, 2026

botnetresidential-proxyproxywaredevice-compromisefbi-seizurealarum-technologiesnetnut

The FBI, working with industry partners, seized hundreds of domains linked to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The takedown follows security research connecting NetNut to the Popa botnet, a network of at least two million devices compromised without meaningful user consent. This represents a significant disruption to a large-scale proxyware/botnet infrastructure used to monetize unwitting victims' internet connections.

Technical Analysis

The Popa botnet reportedly compromises devices via bundled software, SDKs, or malicious applications that silently enroll victim devices as exit nodes in a residential proxy network, enabling traffic anonymization for paying customers of NetNut. No specific CVEs were disclosed in the source reporting, suggesting infection likely occurs through deceptive bundling, third-party app SDKs, or free VPN/software installers rather than exploitation of a software vulnerability. The scale (2M+ devices) indicates a mature distribution pipeline, likely leveraging affiliate monetization schemes common in proxyware ecosystems. The FBI seizure targeted hundreds of domains supporting NetNut's infrastructure, disrupting command, provisioning, and proxy-routing capabilities. Further technical indicators (specific malware families, C2 protocols, hashes) were not provided in available reporting.

Affected Systems

Consumer and possibly enterprise endpoints (Windows, macOS, Android, IoT devices) running bundled proxyware/SDK components; systems with free VPN, ad-supported, or cracked software installed that silently enrolled devices into the residential proxy network.

Indicators of Compromise

  • Domain: netnut[.]io (and hundreds of associated seized domains - full list not published in source)
  • Associated entity: Alarum Technologies Ltd. (NASDAQ: ALAR)
  • Botnet name: Popa

Remediation Steps

  1. 1

    Audit installed software

    Review systems for unauthorized proxyware, free VPN clients, or bundled SDKs that may enroll devices as network exit nodes.

  2. 2

    Network egress monitoring

    Monitor outbound traffic for connections to known NetNut infrastructure and residential proxy relay behavior.

  3. 3

    Remove unauthorized proxy agents

    Uninstall any identified proxyware clients or SDK-bundled applications; scan with updated endpoint protection to remove residual components.

  4. 4

    User awareness training

    Educate users on risks of installing free/cracked software and ad-supported apps that monetize device bandwidth without clear consent.

  5. 5

    Threat intel integration

    Ingest updated domain/IP indicators from law enforcement and security vendor disclosures as they become available to block related infrastructure.

Industries Most Exposed

Consumer/Home UsersTechnologyTelecommunicationsManaged Service ProvidersGeneral Enterprise

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.