appliedbits
FIELD NOTES PUBLISHED
PUBLISHED 2026-07-04

FBI seizes the NetNut residential-proxy platform behind the Popa botnet

Krebs on Security  ·  Brian Krebs  ·  source ↗

Krebs reports the FBI seized hundreds of domains tied to NetNut, a sprawling residential-proxy service run by the publicly-traded Israeli firm Alarum Technologies (NASDAQ: ALAR). The takedown lands about two weeks after Krebs published research from multiple security firms linking NetNut to the Popa botnet — at least two million devices compromised with little or no consent from their owners.

Residential proxies are the plumbing under a lot of modern fraud: they launder automated traffic through real consumer IPs so credential-stuffing, account-takeover, and scam infrastructure look like ordinary subscribers. What makes this one notable is the corporate cover — a NASDAQ-listed company operating the storefront while a two-million-node botnet allegedly supplied the exit nodes. Seizing the platform is the rare enforcement action that hits the infrastructure layer rather than the individual scammer.

One to keep for the cross-channel file: the same proxy layer that hides web fraud increasingly fronts voice and messaging abuse too.

Tagsfraudbotnetresidential-proxyfbi