FBI Seizes NetNut Proxy Service and Popa Botnet Infrastructure

The FBI seized hundreds of domains tied to NetNut, a residential proxy service run by Israeli company Alarum Technologies. The Popa botnet — at least 2 million compromised devices — went down with it.

NetNut’s homepage now shows an FBI seizure banner. The operation involved Google, Lumen, Shadowserver, and the IRS Criminal Investigation division. It follows reporting from KrebsOnSecurity two weeks ago that linked NetNut to the Popa botnet.

How does this work? NetNut distributes software that turns smart TVs and streaming boxes into always-on proxy nodes. Users don’t consent. Their devices become relays for other people’s traffic — scraping, ad fraud, account takeovers.

Google’s Threat Intelligence Group saw 316 distinct threat actor clusters using NetNut exit nodes in a single week in June. That includes both cybercriminal and espionage groups.

Google disabled NetNut-linked accounts and apps that bundle its SDKs. It shared intel on NetNut’s backend infrastructure with law enforcement and researchers.

But here’s the catch. Google warns this is degradation, not elimination. After the IPIDEA takedown earlier this year, proxy operators just bought capacity from competitors and resold it. NetNut’s partners may do the same.

If you have a cheap Android TV box, there’s a decent chance it’s running this stuff. Stick to name-brand hardware. Be careful what apps you install.

References