FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d Convergence

FBI Seizes NetNut Residential Proxy Platform Tied to Popa (TL-2026-1084), also tracked as Popa botnet, is a high-severity botnet operation, first published 2026-07-02. It is attributed to NetNut with medium confidence, affects LG webOS Smart TV app ecosystem, maps to 29 MITRE ATT&CK techniques (T1018, T1021, T1027), and is covered by 9 detection rules and 35 indicators of compromise.

Key facts for TL-2026-1084

Threat ID
TL-2026-1084
Also known as
Popa botnet, Kimwolf botnet, NetNut seizure
Severity
HIGH
Status
ACTIVE
Category
BOTNET
First published
2026-07-02
Last reviewed
2026-07-02
Attribution
NetNut
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
mediaentertainment, technology, ecommerce, financialservices, government administration, pharmacy, foodandbeverage, banking, consumerelectronics
Target regions
Global, North America, Europe, israel
Detection rules
9
Indicators of compromise
35

Malware and tooling in FBI Seizes NetNut Residential Proxy Platform Tied to Popa

Malware and tooling: Popa, RoboVPN, aisuru, kimwolf, vo1d

The FBI and IRS Criminal Investigation, with assistance from Google, Lumen, and Shadowserver, seized domains and infrastructure tied to NetNut, a residential proxy service operated by publicly-traded Alarum Technologies (NASDAQ: ALAR). NetNut/Popa distributed proxy-enlisting SDKs to Android-based smart TVs, streaming boxes, and pirated app ecosystems from LG, Samsung, and generic Android TV manufacturers, converting at least 2 million (researchers estimate 9-26 million total pool) devices into always-on residential proxy nodes used for content scraping, advertising fraud, and account takeover.

How FBI Seizes NetNut Residential Proxy Platform Tied to Popa works

Popa is a multi-year (operating since at least 2022), Android-based residential proxy botnet that silently enlists consumer smart TVs, Android TV boxes, and streaming devices as outbound traffic relays. Independent research from Synthient, Black Lotus Labs (Lumen Technologies), Nokia Deepfield, Spur, and Qurium converged in June 2026 to link Popa's control infrastructure to NetNut, the residential-proxy brand of publicly-traded Alarum Technologies Ltd (NASDAQ: ALAR), an Israeli company. Devices are enlisted via bundled or malicious SDKs embedded in pirated/free streaming apps (e.g., CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams) and, per Spur's app-store analysis, in a startling proportion of official first-party apps — over 42% of LG webOS apps and more than 25% of Samsung Tizen apps were found to embed residential-proxy SDKs (e.g., Plainproxies Byteconnect-style bundlers). Once installed, the SDK establishes a persistent, encrypted communications layer capable of registering the device, maintaining long-lived C2 connections, and opening on-demand tunnels for NetNut's paying proxy customers — traffic resold to over 316 distinct clusters of threat actors observed by Google Threat Intelligence Group (GTIG) using suspected NetNut exit nodes. Nokia Deepfield, monitoring a subset of relay infrastructure, measured 35,000-60,000 simultaneous clients per node and 750,000 unique proxy-egress sources in a 24-hour window; Black Lotus Labs measured 1.5-2.5 million distinct daily IPs against roughly 250-300 control infrastructure addresses. A related, technically distinct but operationally overlapping campaign — Kimwolf — was tracked separately by Synthient founder Benjamin Brundage beginning October 2025 and publicly disclosed by Krebs on Security and SecurityWeek in January 2026. Kimwolf propagates by mass-scanning for Android Debug Bridge (ADB) service exposed on TCP/5555 with no authentication, issuing `adb connect <ip>:5555` to obtain unrestricted root shell access, then using DNS manipulation of RFC-1918 address ranges to tunnel through victim home/enterprise networks and defeat domain-blocklist controls that assume proxy traffic cannot originate from private IP space. Kimwolf shares code and operational lineage with the AISURU DDoS botnet and carries a plugin component associated with the Vo1d botnet family, itself linked to the previously-dismantled Badbox 2.0 operation (Google/HUMAN Security/Trend Micro, July 2025) and to RoboVPN, a VPN app also attributed to NetNut/Alarum. Kimwolf's C2 uses DNS-over-TLS and blockchain-anchored ENS domains for resilience, elliptic-curve-signed and stack-XOR-obfuscated payloads, and has been observed issuing approximately 1.7 billion DDoS commands within a 3-day window, alongside credential-stuffing and residential-proxy-bandwidth monetization. Downstream corporate impact is severe: Infoblox found 65% of its enterprise customer base querying proxy-related domains, with 90% of pharmaceutical/food-and-beverage and 60% of government/banking customers exposed; a COAR survey found over 90% of monitored code repositories experiencing aggressive weekly bot scraping traffic, much of it feeding AI/LLM training pipelines. Following the public research disclosures, Alarum Technologies publicly disputed the findings as 'demonstrably inaccurate assertions and flawed deductions,' characterizing its SDKs as legitimate bandwidth-sharing tools rather than botnet malware. On July 2, 2026, the FBI and IRS Criminal Investigation, assisted by Google, Lumen Technologies, and the Shadowserver Foundation, executed a law-enforcement seizure of hundreds of NetNut-linked domains, disrupting the Popa proxy-resale infrastructure. A central individual named in the research is Moshe Yehuda Kramer (also referred to as Moishi Kramer), who registered NinjaTech SIA in 2020 and serves as SVP Research & Development at NetNut and Chief Strategy & Innovation Officer at Alarum Technologies; NinjaTech's control domain ninjatech[.]io was identified among Popa's control infrastructure despite Kramer's claim that NinjaTech ceased operations roughly five years prior.

MITRE ATT&CK techniques used in TL-2026-1084

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1070 Indicator Removal

Execution

T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1568 Dynamic Resolution; T1573 Encrypted Channel

command-and-control

T1090 Proxy

Credential Access

T1110 Brute Force

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise

Impact

T1496 Resource Hijacking; T1498 Network Denial of Service; T1499 Endpoint Denial of Service

Persistence

T1505 Server Software Component; T1547 Boot or Logon Autostart Execution

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in FBI Seizes NetNut Residential Proxy Platform Tied to Popa

  • LG — webOS Smart TV app ecosystem
    Vulnerable versions: apps distributed via LG Content Store containing bundled proxy SDKs (~42% of analyzed apps)
  • Samsung — Tizen Smart TV app ecosystem
    Vulnerable versions: apps distributed via Samsung app store containing bundled proxy SDKs (>25% of analyzed apps)
  • Generic/unbranded — Android TV boxes and streaming devices (e.g., X96 Mini Box, Superbox, and unbranded models)
    Vulnerable versions: all models shipping with ADB enabled on TCP/5555 and no authentication
  • Various — Digital photo frames running the Uhale app
    Vulnerable versions: Android-based photo frame firmware bundling residential-proxy SDKs
  • Alarum Technologies / NetNut — NetNut residential proxy platform and reseller network
    Vulnerable versions: entire NetNut proxy resale infrastructure prior to 2026-07-02 seizure

Remediation for FBI Seizes NetNut Residential Proxy Platform Tied to Popa

Patches

  • No vendor patch applies; mitigation is configuration (disable ADB), app removal, and network-layer blocking
  • IPIDEA implemented ADB-exploitation-related security patches on 2025-12-25 after coordinated disclosure

Immediate actions

  • Block outbound connections to identified Popa/Kimwolf C2 domains and IP ranges at the perimeter and DNS resolver level
  • Audit and disable ADB (port TCP/5555) on all Android TV boxes, streaming devices, and IoT endpoints; ADB should never be reachable from the network
  • Segment and firewall consumer/IoT devices (smart TVs, streaming boxes, digital photo frames) onto an isolated VLAN separate from corporate and sensitive home-network assets
  • Uninstall known malicious/pirated streaming apps (CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams) and any app requesting excessive background network permissions
  • Reset router DNS settings to trusted resolvers and check for unauthorized DNS configuration changes pointing to RFC-1918 ranges

Workarounds

  • Factory-reset and avoid installing third-party APKs or unofficial streaming apps on Android TV/streaming devices
  • Disable or firewall TCP/5555 on all consumer Android devices

Longer-term hardening

  • Deploy network detection/EDR capable of flagging encrypted long-lived tunnel connections and residential-proxy SDK check-in patterns
  • Vendor due diligence: LG, Samsung, and Android TV OEMs should audit app-store submissions for bundled residential-proxy SDKs (e.g., Plainproxies Byteconnect-style bundlers)
  • Web application operators should deploy bot-mitigation and residential-proxy IP reputation feeds to detect scraping/credential-stuffing/account-takeover traffic riding NetNut/Popa exit nodes
  • Enterprises should monitor for and block DNS queries to known proxy-provider domains identified in Infoblox/GTIG telemetry
  • Track legal/regulatory outcomes of the FBI/IRS-CI seizure and any related SEC disclosure obligations for Alarum Technologies (NASDAQ: ALAR)

Weaknesses (CWE) in FBI Seizes NetNut Residential Proxy Platform Tied to Popa

CWE-1188, CWE-306, CWE-284

Timeline of FBI Seizes NetNut Residential Proxy Platform Tied to Popa

  • Moshe Yehuda Kramer registers NinjaTech SIA, later identified with a control domain (ninjatech[.]io) used by Popa infrastructure.
  • Popa botnet begins enlisting Android-based smart TVs and streaming boxes as residential proxy relay nodes, per multi-firm research timelines.
  • Google, HUMAN Security, and Trend Micro coordinate to dismantle Badbox 2.0 control domains, a botnet family closely associated with Vo1d, which shares a plugin component with Popa.
  • XLab and Synthient founder Benjamin Brundage begin tracking the Kimwolf Android botnet, distinct from but operationally overlapping with Popa.
  • Kimwolf's ADB-based exploitation of IPIDEA proxy-network endpoints is confirmed by researchers.
  • Security researchers notify 11 residential-proxy providers, including IPIDEA, of the ADB exposure enabling Kimwolf infections.
  • IPIDEA implements security patches addressing the ADB exploitation vector following coordinated disclosure.
  • Google legal action leads to the seizure of IPIDEA control domains (China-based competitor proxy network to NetNut).
  • Krebs on Security, SecurityWeek, The Hacker News, and Security Affairs publicly disclose the Kimwolf botnet, reporting 2M+ infected devices and ADB-based ADB-port-5555 exploitation.
  • Qurium identifies mass content-scraping activity using more than 1.4 million residential proxy IPs later linked to Popa/NetNut infrastructure.
  • Spur publishes analysis finding residential-proxy SDKs bundled in over 42% of LG webOS apps and more than 25% of Samsung Tizen apps.
  • Synthient, Black Lotus Labs (Lumen), Nokia Deepfield, and other researchers jointly release findings linking the Popa botnet to NetNut and parent company Alarum Technologies (NASDAQ: ALAR).
  • Krebs on Security publishes 'Popa Botnet Linked to Publicly-Traded Israeli Firm,' naming Moshe Yehuda Kramer and NinjaTech SIA and detailing control domains gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io.
  • Alarum Technologies publicly disputes the research findings, calling them 'demonstrably inaccurate assertions and flawed deductions' and denying its SDKs constitute botnet malware.
  • FBI and IRS Criminal Investigation, assisted by Google, Lumen, and Shadowserver, execute a law-enforcement seizure of hundreds of NetNut-linked domains, disrupting the Popa proxy-resale infrastructure.

Sources cited for FBI Seizes NetNut Residential Proxy Platform Tied to Popa

Threats related to FBI Seizes NetNut Residential Proxy Platform Tied to Popa

Detection coverage for TL-2026-1084

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1084 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats