NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for Password-Spraying and C2 Masking — Threadlinqs Intelligence
As of 2026-07-06, NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for Password-Spraying and C2 Masking is a high-severity iot threat attributed to NetNut, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 51 indicators of compromise.
Threat ID: TL-2026-1112 · Severity: HIGH · Status: ACTIVE · Category: IOT
Updated: 2026-07-06 · revalidated 1× · latest source
Attribution: NetNut · FINANCIAL
Google, the FBI, Lumen, and the Shadowserver Foundation disrupted NetNut (aka "Popa"), a residential proxy botnet operated on infrastructure tied to Alarum Technologies (NASDAQ: ALAR) that enrolled an
NetNut, publicly marketed as a commercial residential-proxy provider by Israeli Nasdaq-listed Alarum Technologies (ALAR), is tracked by independent researchers under the malware family name "Popa" (with related SDK labels Loopop, Neupop, Moneytiser, Hopanet, and Popanet). The underlying proxyware SDK is bundled — without meaningful consent disclosure — into third-party streaming, IPTV, utility, and pirated/modified TV applications such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams, and the VPN app RoboVPN. Independent testing (Spur) found that roughly 42% of ~3,000 sampled LG webOS apps and 25%+ of sampled Samsung Tizen apps contained proxy SDKs, illustrating how deeply the enrollment mechanism penetrated consumer smart-TV app ecosystems. Enrollment also occurs via pre-installed firmware on cheap, uncertified, off-brand Android TV boxes, streaming media boxes, and IPTV devices, frequently overlapping with the BadBox 2.0 and Vo1d Android-TV backdoor ecosystems.
Technically, an enrolled device does not connect directly to a fixed C2 server. Instead it first reaches a rotating set of load-balancer domains (observed by Qurium Media Foundation as gmslb.net, safernetwork.io, tera-home.com, ninjatech.io, phonemesh.org, linkmob.org, peercon.org, phonegrid.org, lbk-sol.com, sklstech.com, and kyc-holdings.com, each exposing an "lb." subdomain), which return the address of an operational backend server of the form s####.<backend_domain>. Communication with the backend then proceeds over TCP port 6000 using a proprietary tunneling/multiplexing scheme researchers call "Popa TLV" (Type-Length-Value framed metadata injected into proxied traffic), implemented via two observed native libraries — libneunative and libalphasdk — that differ only in how they resolve their peer backend server. Related BadBox 2.0 samples load a native library (libanl.so) from the package com.hs.app that decrypts and loads p.jar (module downloader) and q.jar (persistence), invoking Java classes com.hs.cld.Main and com.hs.q.Main; a known BadBox 2.0 C2 domain is catmore88.com. Android package identifiers linked to the Popa SDK variants include io.moneytise, io.popanet, io.nn.lp, io.nn.neunative, and io.nn.nativesdk.
The resulting proxy pool — GTIG estimates at least 2 million devices, with Nokia Deepfield separately measuring 1.5–2.5 million daily active exit IPs and roughly 250–300 controlling internet addresses — is heavily abused by third parties. In a single week in June 2026, GTIG observed 316 distinct cybercriminal and espionage threat clusters using suspected NetNut exit nodes to mask the origin IP address of victim-environment access, infrastructure access, and password-spray attacks. Other documented abuse includes mass content scraping, advertising fraud, and account-takeover campaigns. NetNut's own reseller/white-label program means many ostensibly independent residential-proxy brands (e.g., ProxyJet, DiviNetworks, and Live Proxies, whose CEO is a NetNut alumnus) are, per Google's assessment with high confidence, actually reselling capacity from the same underlying device pool — meaning a single takedown ripples across brands that appear unrelated.
Attribution work by Synthient (founder Benjamin Brundage), Qurium Media Foundation, and Krebs on Security — published June 17–19, 2026 — technically confirmed the Popa-to-NetNut link, including a controlled test in which traffic sent into NetNut's commercial gateway egressed through a device independently confirmed to be Popa-enrolled, and the discovery that C2 domain ninjatech.io is registered to Moishi Kramer, who holds the VP of R&D role at NetNut. Kramer's public response attributed the connection to third-party licensing of legacy code rather than direct operational control. On July 2, 2026, the FBI (with IRS Criminal Investigation) seized netnut.com and hundreds of associated domains, including reseller/supply domains proxyjet.io and divinetworks.com; Alaru
Weaknesses (CWE)
CWE-506, CWE-284, CWE-1188
Target sectors: technology, telecoms, government administration, financialservices, mediaandentertainment, consumerelectronics, criticalinfrastructure
Target regions: Global, North America, Europe, Asia-Pacific, Latin America, brazil, united states of america, mexico
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 51 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
IOT, HIGH, threat intelligence, cybersecurity, T1595, T1583, T1584, T1608, T1195, T1189, T1204, T1129, T1554, T1547