The Federal Bureau of Investigation has seized hundreds of domains associated with NetNut, a residential proxy service operated by the publicly-traded Israeli company Alarum Technologies, following an investigation into the services connection to the Popa botnet.
The action comes approximately two weeks after security researchers from multiple firms published findings linking NetNut to the Popa botnet, a collection of at least two million compromised devices running malicious software with little or no consent from their owners. The botnet has been active for approximately four years, forcing infected Android-based TV boxes and other consumer devices to relay internet traffic used in advertising fraud, account takeovers, and mass data-scraping operations.
Residential proxy services like NetNut allow customers to route their internet traffic through real consumer IP addresses, making it appear as though requests originate from legitimate home users rather than data centers. While these services have legitimate applications in market research and ad verification, they have also become a critical tool for cybercriminals seeking to bypass fraud detection systems and geo-restrictions.
The FBI, working with industry partners, executed the seizure as part of an ongoing effort to disrupt the cybercriminal infrastructure that enables large-scale online fraud. The seized domains include those used by NetNut to manage its proxy network and communicate with clients.
Alarum Technologies, which trades on the Nasdaq stock exchange under the ticker ALAR, has not publicly commented on the seizure. The company has previously stated that NetNut operates as a legitimate proxy service and that it prohibits the use of its infrastructure for illegal activities.
Security researchers have long warned that residential proxy networks create a veil of anonymity that makes it difficult for law enforcement to trace cybercriminal activity back to its source. The NetNut takedown represents one of the most significant enforcement actions against a residential proxy provider to date.
This article was adapted from Krebs on Security. Read the original here.
