NetNut Residential Proxy Botnet (aka Popa) Disrupted by Google and FBI — 2 Million Devices Used for Password-Spraying and C2 Masking

NetNut Residential Proxy Botnet (aka Popa) Disrupted by (TL-2026-1112), also tracked as Popa, is a high-severity IoT security threat, first published 2026-07-03 and last reviewed 2026-07-06. It is attributed to NetNut with medium confidence, affects Alarum Technologies / NetNut NetNut Residential Proxy Network (aka, maps to 32 MITRE ATT&CK techniques (T1001, T1014, T1027), and is covered by 9 detection rules and 51 indicators of compromise.

Key facts for TL-2026-1112

Threat ID
TL-2026-1112
Also known as
Popa, Popa Botnet, NetNut Botnet
Severity
HIGH
Status
ACTIVE
Category
IOT
First published
2026-07-03
Last reviewed
2026-07-06
Attribution
NetNut
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, telecoms, government administration, financialservices, mediaandentertainment, consumerelectronics, criticalinfrastructure
Target regions
Global, North America, Europe, Asia-Pacific, Latin America, brazil, united states of america, mexico
Detection rules
9
Indicators of compromise
51
Updates
2026-07-06 · revalidated 1× · latest source

Malware and tooling in NetNut Residential Proxy Botnet (aka Popa) Disrupted by

Malware and tooling: Badbox 2.0, Popa, aisuru, kimwolf, vo1d, NetNut/Popa Residential Proxy SDK, RoboVPN

Google, the FBI, Lumen, and the Shadowserver Foundation disrupted NetNut (aka "Popa"), a residential proxy botnet operated on infrastructure tied to Alarum Technologies (NASDAQ: ALAR) that enrolled an estimated 2 million devices worldwide via trojanized apps and Badbox 2.0-linked proxy plugins. Google Threat Intelligence Group (GTIG) observed 316 distinct cybercriminal and espionage threat clusters using suspected NetNut exit nodes in a single week in June 2026 to mask password-spraying attacks and other malicious traffic; the FBI seized the netnut.com domain and hundreds of related domains while Google disabled operator accounts and C2 services on its infrastructure.

How NetNut Residential Proxy Botnet (aka Popa) Disrupted by works

NetNut, publicly marketed as a commercial residential-proxy provider by Israeli Nasdaq-listed Alarum Technologies (ALAR), is tracked by independent researchers under the malware family name "Popa" (with related SDK labels Loopop, Neupop, Moneytiser, Hopanet, and Popanet). The underlying proxyware SDK is bundled — without meaningful consent disclosure — into third-party streaming, IPTV, utility, and pirated/modified TV applications such as CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams, and the VPN app RoboVPN. Independent testing (Spur) found that roughly 42% of ~3,000 sampled LG webOS apps and 25%+ of sampled Samsung Tizen apps contained proxy SDKs, illustrating how deeply the enrollment mechanism penetrated consumer smart-TV app ecosystems. Enrollment also occurs via pre-installed firmware on cheap, uncertified, off-brand Android TV boxes, streaming media boxes, and IPTV devices, frequently overlapping with the BadBox 2.0 and Vo1d Android-TV backdoor ecosystems.

Technically, an enrolled device does not connect directly to a fixed C2 server. Instead it first reaches a rotating set of load-balancer domains (observed by Qurium Media Foundation as gmslb.net, safernetwork.io, tera-home.com, ninjatech.io, phonemesh.org, linkmob.org, peercon.org, phonegrid.org, lbk-sol.com, sklstech.com, and kyc-holdings.com, each exposing an "lb." subdomain), which return the address of an operational backend server of the form s####.<backend_domain>. Communication with the backend then proceeds over TCP port 6000 using a proprietary tunneling/multiplexing scheme researchers call "Popa TLV" (Type-Length-Value framed metadata injected into proxied traffic), implemented via two observed native libraries — libneunative and libalphasdk — that differ only in how they resolve their peer backend server. Related BadBox 2.0 samples load a native library (libanl.so) from the package com.hs.app that decrypts and loads p.jar (module downloader) and q.jar (persistence), invoking Java classes com.hs.cld.Main and com.hs.q.Main; a known BadBox 2.0 C2 domain is catmore88.com. Android package identifiers linked to the Popa SDK variants include io.moneytise, io.popanet, io.nn.lp, io.nn.neunative, and io.nn.nativesdk.

The resulting proxy pool — GTIG estimates at least 2 million devices, with Nokia Deepfield separately measuring 1.5–2.5 million daily active exit IPs and roughly 250–300 controlling internet addresses — is heavily abused by third parties. In a single week in June 2026, GTIG observed 316 distinct cybercriminal and espionage threat clusters using suspected NetNut exit nodes to mask the origin IP address of victim-environment access, infrastructure access, and password-spray attacks. Other documented abuse includes mass content scraping, advertising fraud, and account-takeover campaigns. NetNut's own reseller/white-label program means many ostensibly independent residential-proxy brands (e.g., ProxyJet, DiviNetworks, and Live Proxies, whose CEO is a NetNut alumnus) are, per Google's assessment with high confidence, actually reselling capacity from the same underlying device pool — meaning a single takedown ripples across brands that appear unrelated.

Attribution work by Synthient (founder Benjamin Brundage), Qurium Media Foundation, and Krebs on Security — published June 17–19, 2026 — technically confirmed the Popa-to-NetNut link, including a controlled test in which traffic sent into NetNut's commercial gateway egressed through a device independently confirmed to be Popa-enrolled, and the discovery that C2 domain ninjatech.io is registered to Moishi Kramer, who holds the VP of R&D role at NetNut. Kramer's public response attributed the connection to third-party licensing of legacy code rather than direct operational control. On July 2, 2026, the FBI (with IRS Criminal Investigation) seized netnut.com and hundreds of associated domains, including reseller/supply domains proxyjet.io and divinetworks.com; Alarum Technologies disclosed the seizures in SEC/press filings and stated it would cooperate with law enforcement. Google simultaneously disabled Google accounts and services used by NetNut for C2 (a Terms of Service/Acceptable Use Policy violation), updated Google Play Protect to flag apps bundling NetNut/Popa SDKs, and shared SDK/C2 technical intelligence with platform providers and researchers. This action follows Google's January 2026 disruption of the comparable IPIDEA residential proxy network (550+ threat groups observed abusing it in one week, including China-, DPRK-, Iran-, and Russia-linked clusters) and sits within a broader 2025–2026 enforcement wave against Android-proxy-abuse botnets including BadBox 2.0, Vo1d, and the DDoS-focused Aisuru/Kimwolf/JackSkid/Mossad family (disrupted by DOJ court order in March 2026). Despite the netnut.com seizure, the netnut.io storefront reportedly remains operational, and downstream white-label resellers continue operating, indicating substantial residual risk from this device-enrollment ecosystem beyond the single domain seizure.

MITRE ATT&CK techniques used in TL-2026-1112

Command and Control

T1001 Data Obfuscation; T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1568 Dynamic Resolution; T1571 Non-Standard Port; T1573 Encrypted Channel

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading

Exfiltration

T1041 Exfiltration Over C2 Channel

Initial Access

T1078 Valid Accounts; T1189 Drive-by Compromise; T1195 Supply Chain Compromise

Discovery

T1082 System Information Discovery

Credential Access

T1110 Brute Force

Collection

T1119 Automated Collection

Execution

T1129 Shared Modules; T1204 User Execution

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1496 Resource Hijacking; T1498 Network Denial of Service; T1657 Financial Theft

Persistence

T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities

Reconnaissance

T1595 Active Scanning

defense-impairment

T1599 Network Boundary Bridging; T1685 Disable or Modify Tools

Affected products and versions in NetNut Residential Proxy Botnet (aka Popa) Disrupted by

  • Alarum Technologies / NetNut — NetNut Residential Proxy Network (aka Popa botnet)
    Vulnerable versions: All NetNut proxy infrastructure and reseller capacity operating prior to the July 2, 2026 domain seizure
    Fixed in: N/A — netnut.com seized; netnut.io and reseller brands (ProxyJet, DiviNetworks, Live Proxies) reportedly still operational
  • Generic / Off-brand OEMs — Android TV boxes, streaming media boxes, and IPTV devices (uncertified AOSP builds)
    Vulnerable versions: Devices with pre-installed Popa/Badbox 2.0 firmware or running trojanized apps (CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams, RoboVPN)
    Fixed in: N/A — requires device replacement or app/firmware remediation
  • LG — webOS smart-TV application ecosystem
    Vulnerable versions: ~42% of ~3,000 sampled apps found bundling residential-proxy SDKs (Spur analysis)
    Fixed in: N/A — app-store hygiene/vetting issue, not a firmware CVE
  • Samsung — Tizen smart-TV application ecosystem
    Vulnerable versions: 25%+ of sampled apps found bundling residential-proxy components (Spur analysis)
    Fixed in: N/A — app-store hygiene/vetting issue, not a firmware CVE

Remediation for NetNut Residential Proxy Botnet (aka Popa) Disrupted by

Patches

  • No vendor patch applies — remediation requires device replacement, firmware reflash, or removal of the offending app/SDK
  • Google Play Protect has been updated to detect and warn about applications bundling NetNut/Popa SDKs

Immediate actions

  • Block known NetNut/Popa C2 and load-balancer domains (netnut.com, netnut.io, gmslb.net, safernetwork.io, tera-home.com, ninjatech.io, phonemesh.org, linkmob.org, peercon.org, phonegrid.org, lbk-sol.com, sklstech.com, kyc-holdings.com, catmore88.com) and reseller domains (proxyjet.io, divinetworks.com) at DNS/perimeter firewalls
  • Audit smart-TV and Android streaming-device app inventories for known trojanized apps (CRICFy, DooFlix, Sprozfy, RTS Tv, Flixoid, CyberFlix, Rapid Streamz, TvMob, HD/OceanStreams, RoboVPN) and remove them
  • Alert on outbound TCP/6000 connections and TLV-framed proxy tunnel traffic from consumer/IoT network segments
  • Treat authentication attempts sourced from residential-proxy IP ranges (including former/current NetNut, ProxyJet, DiviNetworks, Live Proxies exit nodes) as higher risk for password-spray correlation

Workarounds

  • Factory-reset affected TV boxes/streaming devices and avoid sideloading APKs from unofficial marketplaces
  • Disable or restrict Android Debug Bridge (ADB) exposure on IoT/streaming devices to prevent related botnets (e.g., Kimwolf) from pivoting through them

Longer-term hardening

  • Replace uncertified, off-brand Android TV boxes/streaming devices/IPTV units with Google Play Protect-certified hardware
  • Segment consumer IoT and smart-TV devices onto isolated network VLANs separate from corporate/sensitive assets
  • Deploy DNS filtering/threat-intel feeds that continuously ingest emerging Popa/Badbox/Vo1d C2 domains, since infrastructure rotates quickly after takedowns
  • Implement behavioral/UEBA detection for password-spray patterns and impossible-travel logins irrespective of source IP reputation, since residential-proxy abuse defeats geo/IP-reputation-only controls

Weaknesses (CWE) in NetNut Residential Proxy Botnet (aka Popa) Disrupted by

CWE-506, CWE-284, CWE-1188

Timeline of NetNut Residential Proxy Botnet (aka Popa) Disrupted by

Showing the 20 most recent tracked events.

  • The Kimwolf Android variant of the Aisuru DDoS botnet becomes highly active, later found to spread by tunneling through residential-proxy connections (NetNut/IPIDEA) into victims' local networks to infect additional in-network devices behind the firewall.
  • New Popa control-domain infrastructure is registered in the months following the BadBox 2.0 takedown, later assessed by researchers as a continuation of the same device-enrollment ecosystem under new SDK branding (Loopop, Neupop, Moneytiser).
  • Synthient researcher Benjamin Brundage and KrebsOnSecurity publish research documenting a one-to-one overlap between new Kimwolf infections and IPIDEA-rented residential proxy IP addresses, establishing the residential-proxy-abuse propagation vector shared with NetNut/Popa.
  • SecurityWeek reports Kimwolf has grown to more than 2 million infected Android devices by exploiting residential-proxy connections — the same abuse technique later documented for the NetNut/Popa ecosystem.
  • Researchers and Krebs on Security report the Kimwolf Android botnet infecting roughly 2 million devices by abusing exposed Android Debug Bridge (ADB) ports reachable through residential proxy networks including IPIDEA.
  • Google Threat Intelligence Group, partnered with Cloudflare, discloses disruption of the IPIDEA residential proxy network after observing 550+ distinct threat groups — including China-, DPRK-, Iran-, and Russia-linked clusters — using IPIDEA exit nodes in a single week.
  • KrebsOnSecurity publicly names 'Dort' (later identified as Jacob Butler, Ottawa, Canada) as the suspected Kimwolf botmaster after he launches retaliatory DDoS, doxing, and swatting campaigns against the reporter and a security researcher.
  • Law enforcement executes a search warrant at the Ottawa, Canada residence of Jacob Butler ('Dort'), seizing multiple devices as part of the coordinated international Aisuru/Kimwolf investigation.
  • The U.S. Department of Justice announces court-authorized disruption of command-and-control servers supporting the Aisuru, Kimwolf, JackSkid, and Mossad DDoS botnets, part of the same Android-proxy-abuse ecosystem.
  • The U.S. Department of Justice, with law enforcement partners in Germany and Canada, announces an international operation disrupting the Aisuru, Kimwolf, JackSkid, and Mossad IoT DDoS botnet family, which by then spanned more than 3 million compromised DVRs, cameras, routers, and other devices reliant on residential-proxy infrastructure including NetNut/Popa.
  • A criminal complaint against Jacob Butler ('Dort') is unsealed in Alaska federal court; he is arrested and charged in both Canada and the U.S. for building and operating the Kimwolf DDoS botnet that leveraged NetNut/IPIDEA residential-proxy infrastructure for lateral network spread and DDoS traffic origination.
  • Synthient founder Benjamin Brundage runs a controlled test showing a Popa-enrolled consumer device egressing traffic through NetNut's commercial proxy gateway, technically confirming Popa devices operate as NetNut exit nodes.
  • Krebs on Security, Synthient, and the Qurium Media Foundation publish coordinated technical findings linking the Popa botnet to NetNut and parent company Alarum Technologies, including the discovery that C2 domain ninjatech.io is registered to NetNut VP of R&D Moishi Kramer.
  • In a single week in June 2026, GTIG observes 316 distinct threat clusters — spanning cybercriminal and state-linked espionage operations — using suspected NetNut exit nodes to conduct password-spraying, credential-stuffing, account-takeover, advertising fraud, and sensitive data-scraping campaigns against victim environments.
  • Google disables Google accounts and services used by NetNut for command-and-control in violation of its Terms of Service, and updates Google Play Protect to flag applications bundling NetNut/Popa SDKs.
  • The FBI, with IRS Criminal Investigation, seizes netnut.com and hundreds of associated domains, including reseller/supply domains proxyjet.io and divinetworks.com, tied to the NetNut/Popa proxy network.
  • Additional NetNut-associated domains, including netnut.io, have their nameservers redirected to FBI-controlled servers (ns1/ns2.fbi.seized.gov); Alarum Technologies files additional Form 6-K disclosures acknowledging ongoing service disruption — contradicting the initial assessment that netnut.io remained operational.
  • The Register, BleepingComputer, and other outlets publicly report the joint Google/FBI/Lumen/Shadowserver disruption of the roughly 2-million-device NetNut/Popa residential proxy botnet, citing GTIG's observation of 316 distinct cybercriminal and espionage threat clusters using NetNut exit nodes in a single week in June 2026.
  • Despite the netnut.com seizure, the netnut.io storefront and downstream white-label resellers (e.g., ProxyJet, Live Proxies) reportedly remain operational, indicating the underlying device-enrollment infrastructure and demand persist beyond this disruption action.
  • Alarum Technologies files a Form 6-K stating NetNut has temporarily paused traffic through the affected network services for several days as a precautionary measure while it investigates the FBI seizure and its operational impact; Malwarebytes publishes consumer-facing guidance on avoiding proxyware botnets.

Update history for TL-2026-1112

Sources cited for NetNut Residential Proxy Botnet (aka Popa) Disrupted by

Threats related to NetNut Residential Proxy Botnet (aka Popa) Disrupted by

Detection coverage for TL-2026-1112

As of 2026-07-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1112 across Splunk SPL, Microsoft KQL and Sigma, covering 51 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats