FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d Convergence
FBI Seizes NetNut Residential Proxy Platform Tied to Popa (TL-2026-1084), also tracked as Popa botnet, is a high-severity botnet operation, first published 2026-07-02. It is attributed to NetNut with medium confidence, affects LG webOS Smart TV app ecosystem, maps to 29 MITRE ATT&CK techniques (T1018, T1021, T1027), and is covered by 9 detection rules and 35 indicators of compromise.
Key facts for TL-2026-1084
- Threat ID
- TL-2026-1084
- Also known as
- Popa botnet, Kimwolf botnet, NetNut seizure
- Severity
- HIGH
- Status
- ACTIVE
- Category
- BOTNET
- First published
- 2026-07-02
- Last reviewed
- 2026-07-02
- Attribution
- NetNut
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- mediaentertainment, technology, ecommerce, financialservices, government administration, pharmacy, foodandbeverage, banking, consumerelectronics
- Target regions
- Global, North America, Europe, israel
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in FBI Seizes NetNut Residential Proxy Platform Tied to Popa
Malware and tooling: Popa, RoboVPN, aisuru, kimwolf, vo1d
The FBI and IRS Criminal Investigation, with assistance from Google, Lumen, and Shadowserver, seized domains and infrastructure tied to NetNut, a residential proxy service operated by publicly-traded Alarum Technologies (NASDAQ: ALAR). NetNut/Popa distributed proxy-enlisting SDKs to Android-based smart TVs, streaming boxes, and pirated app ecosystems from LG, Samsung, and generic Android TV manufacturers, converting at least 2 million (researchers estimate 9-26 million total pool) devices into always-on residential proxy nodes used for content scraping, advertising fraud, and account takeover.
How FBI Seizes NetNut Residential Proxy Platform Tied to Popa works
Popa is a multi-year (operating since at least 2022), Android-based residential proxy botnet that silently enlists consumer smart TVs, Android TV boxes, and streaming devices as outbound traffic relays. Independent research from Synthient, Black Lotus Labs (Lumen Technologies), Nokia Deepfield, Spur, and Qurium converged in June 2026 to link Popa's control infrastructure to NetNut, the residential-proxy brand of publicly-traded Alarum Technologies Ltd (NASDAQ: ALAR), an Israeli company. Devices are enlisted via bundled or malicious SDKs embedded in pirated/free streaming apps (e.g., CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams) and, per Spur's app-store analysis, in a startling proportion of official first-party apps — over 42% of LG webOS apps and more than 25% of Samsung Tizen apps were found to embed residential-proxy SDKs (e.g., Plainproxies Byteconnect-style bundlers). Once installed, the SDK establishes a persistent, encrypted communications layer capable of registering the device, maintaining long-lived C2 connections, and opening on-demand tunnels for NetNut's paying proxy customers — traffic resold to over 316 distinct clusters of threat actors observed by Google Threat Intelligence Group (GTIG) using suspected NetNut exit nodes. Nokia Deepfield, monitoring a subset of relay infrastructure, measured 35,000-60,000 simultaneous clients per node and 750,000 unique proxy-egress sources in a 24-hour window; Black Lotus Labs measured 1.5-2.5 million distinct daily IPs against roughly 250-300 control infrastructure addresses. A related, technically distinct but operationally overlapping campaign — Kimwolf — was tracked separately by Synthient founder Benjamin Brundage beginning October 2025 and publicly disclosed by Krebs on Security and SecurityWeek in January 2026. Kimwolf propagates by mass-scanning for Android Debug Bridge (ADB) service exposed on TCP/5555 with no authentication, issuing `adb connect <ip>:5555` to obtain unrestricted root shell access, then using DNS manipulation of RFC-1918 address ranges to tunnel through victim home/enterprise networks and defeat domain-blocklist controls that assume proxy traffic cannot originate from private IP space. Kimwolf shares code and operational lineage with the AISURU DDoS botnet and carries a plugin component associated with the Vo1d botnet family, itself linked to the previously-dismantled Badbox 2.0 operation (Google/HUMAN Security/Trend Micro, July 2025) and to RoboVPN, a VPN app also attributed to NetNut/Alarum. Kimwolf's C2 uses DNS-over-TLS and blockchain-anchored ENS domains for resilience, elliptic-curve-signed and stack-XOR-obfuscated payloads, and has been observed issuing approximately 1.7 billion DDoS commands within a 3-day window, alongside credential-stuffing and residential-proxy-bandwidth monetization. Downstream corporate impact is severe: Infoblox found 65% of its enterprise customer base querying proxy-related domains, with 90% of pharmaceutical/food-and-beverage and 60% of government/banking customers exposed; a COAR survey found over 90% of monitored code repositories experiencing aggressive weekly bot scraping traffic, much of it feeding AI/LLM training pipelines. Following the public research disclosures, Alarum Technologies publicly disputed the findings as 'demonstrably inaccurate assertions and flawed deductions,' characterizing its SDKs as legitimate bandwidth-sharing tools rather than botnet malware. On July 2, 2026, the FBI and IRS Criminal Investigation, assisted by Google, Lumen Technologies, and the Shadowserver Foundation, executed a law-enforcement seizure of hundreds of NetNut-linked domains, disrupting the Popa proxy-resale infrastructure. A central individual named in the research is Moshe Yehuda Kramer (also referred to as Moishi Kramer), who registered NinjaTech SIA in 2020 and serves as SVP Research & Development at NetNut and Chief Strategy & Innovation Officer at Alarum Technologies; NinjaTech's control domain ninjatech[.]io was identified among Popa's control infrastructure despite Kramer's claim that NinjaTech ceased operations roughly five years prior.
MITRE ATT&CK techniques used in TL-2026-1084
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal
Execution
T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1568 Dynamic Resolution; T1573 Encrypted Channel
command-and-control
Credential Access
Collection
T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise
Impact
T1496 Resource Hijacking; T1498 Network Denial of Service; T1499 Endpoint Denial of Service
Persistence
T1505 Server Software Component; T1547 Boot or Logon Autostart Execution
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
defense-impairment
Affected products and versions in FBI Seizes NetNut Residential Proxy Platform Tied to Popa
- LG — webOS Smart TV app ecosystem
Vulnerable versions: apps distributed via LG Content Store containing bundled proxy SDKs (~42% of analyzed apps) - Samsung — Tizen Smart TV app ecosystem
Vulnerable versions: apps distributed via Samsung app store containing bundled proxy SDKs (>25% of analyzed apps) - Generic/unbranded — Android TV boxes and streaming devices (e.g., X96 Mini Box, Superbox, and unbranded models)
Vulnerable versions: all models shipping with ADB enabled on TCP/5555 and no authentication - Various — Digital photo frames running the Uhale app
Vulnerable versions: Android-based photo frame firmware bundling residential-proxy SDKs - Alarum Technologies / NetNut — NetNut residential proxy platform and reseller network
Vulnerable versions: entire NetNut proxy resale infrastructure prior to 2026-07-02 seizure
Remediation for FBI Seizes NetNut Residential Proxy Platform Tied to Popa
Patches
- No vendor patch applies; mitigation is configuration (disable ADB), app removal, and network-layer blocking
- IPIDEA implemented ADB-exploitation-related security patches on 2025-12-25 after coordinated disclosure
Immediate actions
- Block outbound connections to identified Popa/Kimwolf C2 domains and IP ranges at the perimeter and DNS resolver level
- Audit and disable ADB (port TCP/5555) on all Android TV boxes, streaming devices, and IoT endpoints; ADB should never be reachable from the network
- Segment and firewall consumer/IoT devices (smart TVs, streaming boxes, digital photo frames) onto an isolated VLAN separate from corporate and sensitive home-network assets
- Uninstall known malicious/pirated streaming apps (CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams) and any app requesting excessive background network permissions
- Reset router DNS settings to trusted resolvers and check for unauthorized DNS configuration changes pointing to RFC-1918 ranges
Workarounds
- Factory-reset and avoid installing third-party APKs or unofficial streaming apps on Android TV/streaming devices
- Disable or firewall TCP/5555 on all consumer Android devices
Longer-term hardening
- Deploy network detection/EDR capable of flagging encrypted long-lived tunnel connections and residential-proxy SDK check-in patterns
- Vendor due diligence: LG, Samsung, and Android TV OEMs should audit app-store submissions for bundled residential-proxy SDKs (e.g., Plainproxies Byteconnect-style bundlers)
- Web application operators should deploy bot-mitigation and residential-proxy IP reputation feeds to detect scraping/credential-stuffing/account-takeover traffic riding NetNut/Popa exit nodes
- Enterprises should monitor for and block DNS queries to known proxy-provider domains identified in Infoblox/GTIG telemetry
- Track legal/regulatory outcomes of the FBI/IRS-CI seizure and any related SEC disclosure obligations for Alarum Technologies (NASDAQ: ALAR)
Weaknesses (CWE) in FBI Seizes NetNut Residential Proxy Platform Tied to Popa
CWE-1188, CWE-306, CWE-284
Timeline of FBI Seizes NetNut Residential Proxy Platform Tied to Popa
- Moshe Yehuda Kramer registers NinjaTech SIA, later identified with a control domain (ninjatech[.]io) used by Popa infrastructure.
- Popa botnet begins enlisting Android-based smart TVs and streaming boxes as residential proxy relay nodes, per multi-firm research timelines.
- Google, HUMAN Security, and Trend Micro coordinate to dismantle Badbox 2.0 control domains, a botnet family closely associated with Vo1d, which shares a plugin component with Popa.
- XLab and Synthient founder Benjamin Brundage begin tracking the Kimwolf Android botnet, distinct from but operationally overlapping with Popa.
- Kimwolf's ADB-based exploitation of IPIDEA proxy-network endpoints is confirmed by researchers.
- Security researchers notify 11 residential-proxy providers, including IPIDEA, of the ADB exposure enabling Kimwolf infections.
- IPIDEA implements security patches addressing the ADB exploitation vector following coordinated disclosure.
- Google legal action leads to the seizure of IPIDEA control domains (China-based competitor proxy network to NetNut).
- Krebs on Security, SecurityWeek, The Hacker News, and Security Affairs publicly disclose the Kimwolf botnet, reporting 2M+ infected devices and ADB-based ADB-port-5555 exploitation.
- Qurium identifies mass content-scraping activity using more than 1.4 million residential proxy IPs later linked to Popa/NetNut infrastructure.
- Spur publishes analysis finding residential-proxy SDKs bundled in over 42% of LG webOS apps and more than 25% of Samsung Tizen apps.
- Synthient, Black Lotus Labs (Lumen), Nokia Deepfield, and other researchers jointly release findings linking the Popa botnet to NetNut and parent company Alarum Technologies (NASDAQ: ALAR).
- Krebs on Security publishes 'Popa Botnet Linked to Publicly-Traded Israeli Firm,' naming Moshe Yehuda Kramer and NinjaTech SIA and detailing control domains gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io.
- Alarum Technologies publicly disputes the research findings, calling them 'demonstrably inaccurate assertions and flawed deductions' and denying its SDKs constitute botnet malware.
- FBI and IRS Criminal Investigation, assisted by Google, Lumen, and Shadowserver, execute a law-enforcement seizure of hundreds of NetNut-linked domains, disrupting the Popa proxy-resale infrastructure.
Sources cited for FBI Seizes NetNut Residential Proxy Platform Tied to Popa
- FBI Seizes NetNut Proxy Platform, Popa Botnet
- 'Popa' Botnet Linked to Publicly-Traded Israeli Firm
- The Kimwolf Botnet is Stalking Your Local Network
- Kimwolf Android Botnet Grows Through Residential Proxy Networks
- Kimwolf botnet leverages residential proxies to hijack 2M+ Android devices
- Kimwolf Android Botnet: Massive Infection of Smart TVs, IoT Devices, and TV Boxes via Exposed ADB and Residential Proxy Networks
- Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks
- Popa Botnet Linked to NetNut/Alarum Technologies: Inside the Residential Proxy Network Fueling AI Scraping
- Security Researchers Link 'Popa' Botnet to Israeli Proxy Provider NetNut
- Your Smart TV Is Secretly Routing Hacker Traffic
- Kimwolf Android Botnet: Massive Android TV Box and IoT Malware Threat Exploiting Global Networks
- Kimwolf Android Botnet Exploits Residential Proxies to Breach Internal Networks
- public-research/cecbot report
Threats related to FBI Seizes NetNut Residential Proxy Platform Tied to Popa
- NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for Password-Spraying and C2 Masking
- Popa Botnet — Android TV Box Residential-Proxy Malware (Vo1d/Mzmess Plugin) Linked to NetNut / Alarum Technologies
- SimpleHelp Authentication Bypass via Forged OIDC Tokens (CVE-2026-48558) Actively Exploited, Added to CISA KEV
Detection coverage for TL-2026-1084
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1084 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.