FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d Convergence — Threadlinqs Intelligence
As of 2026-07-02, FBI Seizes NetNut Residential Proxy Platform Tied to Popa Botnet (2M+ Devices) — Alarum Technologies, Kimwolf/Vo1d Convergence is a high-severity botnet threat attributed to NetNut, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-1084 · Severity: HIGH · Status: ACTIVE · Category: BOTNET
Attribution: NetNut · FINANCIAL
The FBI and IRS Criminal Investigation, with assistance from Google, Lumen, and Shadowserver, seized domains and infrastructure tied to NetNut, a residential proxy service operated by publicly-traded
Popa is a multi-year (operating since at least 2022), Android-based residential proxy botnet that silently enlists consumer smart TVs, Android TV boxes, and streaming devices as outbound traffic relays. Independent research from Synthient, Black Lotus Labs (Lumen Technologies), Nokia Deepfield, Spur, and Qurium converged in June 2026 to link Popa's control infrastructure to NetNut, the residential-proxy brand of publicly-traded Alarum Technologies Ltd (NASDAQ: ALAR), an Israeli company. Devices are enlisted via bundled or malicious SDKs embedded in pirated/free streaming apps (e.g., CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams) and, per Spur's app-store analysis, in a startling proportion of official first-party apps — over 42% of LG webOS apps and more than 25% of Samsung Tizen apps were found to embed residential-proxy SDKs (e.g., Plainproxies Byteconnect-style bundlers). Once installed, the SDK establishes a persistent, encrypted communications layer capable of registering the device, maintaining long-lived C2 connections, and opening on-demand tunnels for NetNut's paying proxy customers — traffic resold to over 316 distinct clusters of threat actors observed by Google Threat Intelligence Group (GTIG) using suspected NetNut exit nodes. Nokia Deepfield, monitoring a subset of relay infrastructure, measured 35,000-60,000 simultaneous clients per node and 750,000 unique proxy-egress sources in a 24-hour window; Black Lotus Labs measured 1.5-2.5 million distinct daily IPs against roughly 250-300 control infrastructure addresses. A related, technically distinct but operationally overlapping campaign — Kimwolf — was tracked separately by Synthient founder Benjamin Brundage beginning October 2025 and publicly disclosed by Krebs on Security and SecurityWeek in January 2026. Kimwolf propagates by mass-scanning for Android Debug Bridge (ADB) service exposed on TCP/5555 with no authentication, issuing `adb connect <ip>:5555` to obtain unrestricted root shell access, then using DNS manipulation of RFC-1918 address ranges to tunnel through victim home/enterprise networks and defeat domain-blocklist controls that assume proxy traffic cannot originate from private IP space. Kimwolf shares code and operational lineage with the AISURU DDoS botnet and carries a plugin component associated with the Vo1d botnet family, itself linked to the previously-dismantled Badbox 2.0 operation (Google/HUMAN Security/Trend Micro, July 2025) and to RoboVPN, a VPN app also attributed to NetNut/Alarum. Kimwolf's C2 uses DNS-over-TLS and blockchain-anchored ENS domains for resilience, elliptic-curve-signed and stack-XOR-obfuscated payloads, and has been observed issuing approximately 1.7 billion DDoS commands within a 3-day window, alongside credential-stuffing and residential-proxy-bandwidth monetization. Downstream corporate impact is severe: Infoblox found 65% of its enterprise customer base querying proxy-related domains, with 90% of pharmaceutical/food-and-beverage and 60% of government/banking customers exposed; a COAR survey found over 90% of monitored code repositories experiencing aggressive weekly bot scraping traffic, much of it feeding AI/LLM training pipelines. Following the public research disclosures, Alarum Technologies publicly disputed the findings as 'demonstrably inaccurate assertions and flawed deductions,' characterizing its SDKs as legitimate bandwidth-sharing tools rather than botnet malware. On July 2, 2026, the FBI and IRS Criminal Investigation, assisted by Google, Lumen Technologies, and the Shadowserver Foundation, executed a law-enforcement seizure of hundreds of NetNut-linked domains, disrupting the Popa proxy-resale infrastructure. A central individual named in the research is Moshe Yehuda Kramer (also referred to as Moishi Kramer), who registered NinjaTech SIA in 2020 and serves as SVP Research & Development at NetNut and Chief Strategy & Innovation Officer at Alarum Technologies;
Weaknesses (CWE)
CWE-1188, CWE-306, CWE-284
Target sectors: mediaentertainment, technology, ecommerce, financialservices, government administration, pharmacy, foodandbeverage, banking, consumerelectronics
Target regions: Global, North America, Europe, israel
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
BOTNET, HIGH, threat intelligence, cybersecurity, T1595, T1583, T1583, T1587, T1195, T1190, T1133, T1059, T1072, T1547