FBI Seizes NetNut and Popa Botnet: Practitioner Analysis
The FBI seized NetNut's proxy infrastructure and the Popa botnet. Here's what the action means for red teamers, SOC analysts, and OSINT practitioners.
Two weeks after independent security researchers published attribution connecting NetNut to the Popa botnet, the FBI seized hundreds of domains tied to that infrastructure. NetNut is not a dark-web operation — it belongs to Alarum Technologies, a publicly traded Israeli company on NASDAQ. That detail matters more than the headline number.
What Actually Happened
According to KrebsOnSecurity’s reporting, federal agents coordinated with industry partners to seize domains across NetNut’s residential proxy network, which had been tied to the Popa botnet — at least two million compromised devices enrolled without meaningful consent. The seizure followed published findings from multiple security firms by roughly two weeks.
That timeline is not incidental. Private-sector researchers did the attribution groundwork; the FBI moved on the evidentiary record the research created. The bureau did not stumble onto Popa. This is now an established pattern, and OSINT practitioners should internalize it.
Also worth sitting with: Alarum Technologies had a commercial website, investor relations pages, and a LinkedIn presence. If that doesn’t shift how you think about the threat surface residential proxy services represent, it should.
Why Residential Proxy Networks Are Structurally Broken
Legitimate use cases for residential proxies exist — ad verification, brand protection, price comparison research. The economic model, however, depends on aggregating IPs from real consumer devices, and the recruitment methods for those devices are where things come apart.
The Popa allegation is the cleanest version of the core problem. When a proxy pool is sourced — even partially — from malware-infected or deceptively enrolled devices, every customer transaction routes through a victim’s connection. A penetration tester buying residential proxies for red team work, a threat intel analyst scraping paste sites, or a corporate investigator doing competitive research may be unknowingly routing through an active criminal operation.
The FBI’s 2023 IC3 advisory on residential proxy abuse made explicit that nation-state actors routinely use residential proxy pools to defeat geolocation-based blocking and attribution. Popa is not an isolated event; it fits a documented enforcement trajectory.
A 2024 Stanford Internet Observatory analysis of proxy network enrollment practices found a significant share of devices in commercial residential pools were enrolled through SDK bundling in free applications, with consent buried in terms of service. The legal distance between “consensual” and “compromised” is smaller than most proxy providers — or their customers — want to acknowledge.
Implications for Offensive Security Practitioners
For red teamers and penetration testers, this action warrants an immediate review of proxy procurement.
Know your vendor’s sourcing model
If a residential proxy provider cannot clearly articulate how devices are enrolled, what consent mechanisms exist, and whether its pool has been independently audited, treat it as high-risk. “We have millions of IPs” is a marketing claim, not a compliance posture.
Botnet-sourced proxies create legal exposure
Using infrastructure that is later seized or tied to criminal activity creates evidentiary complications for engagements. Your client’s legal team will not enjoy explaining to a regulator why red team traffic transited a federally seized network.
Attribution erosion works both ways
Residential proxies evade geo-blocks and IP reputation filters — that’s the point. But if those IPs are simultaneously used by actual threat actors sharing the same botnet pool, your traffic is co-mingled with genuine malicious activity in defender logs. That is bad for triage and worse for client relationships.
Backfill past engagements
If your team used NetNut proxies in the past 18–24 months, consider whether engagement artifacts — connection logs, screenshots, exfil test data — could surface in seized infrastructure. Brief legal counsel before that question comes from outside your organization.
Implications for Defensive Teams and Threat Intelligence
For blue teamers and SOC analysts, the Popa seizure is simultaneously good news and analytically messy.
What the seizure gives you
Two million compromised devices is a non-trivial reduction in adversary-accessible residential IP space. Threat actors relying on Popa-sourced proxies to evade blocklists will need to reestablish footholds elsewhere. That shift creates a detectable gap — campaigns that were stealthy may become more visible as actors migrate to less-vetted proxies with weaker reputation scores.
What the seizure does not resolve
Seized domains are known-bad at the time of seizure. Botnets are not static. The malware that enrolled Popa’s two million devices is still resident on those machines unless users actively remediate. C2 may shift; affiliated actors may spin up new infrastructure with overlapping TTPs. Treat the seizure as a phase transition, not a resolution.
Detection actions to run now
- Pull the seized domain list (via DOJ press release or court filings once published) and backfill against DNS query logs and proxy logs for the past 90 days. Any internal host that resolved a Popa-associated domain warrants investigation.
- Pull Popa IOCs from the security firms cited in the KrebsOnSecurity reporting. Their published research may include IP ranges, hashes, or behavioral signatures your SIEM can operationalize today.
- Audit egress filtering for residential proxy ranges. Most organizations block datacenter IP ranges but have blind spots on commercial residential proxies — whether employees are using them on corporate devices or attackers are using them to blend into allowed traffic.
The OSINT Angle: Research Preceding Enforcement
The Popa case is a clean example of how open-source research translates into law enforcement outcomes. The sequence — private-sector researchers identify the botnet, publish findings, FBI seizes infrastructure two weeks later — reflects deliberate analytical work, not coincidence.
Infrastructure pivoting built the case
The connection between NetNut (commercial, public-facing) and Popa (botnet) came from AS number analysis, passive DNS correlation, certificate transparency log review, and behavioral fingerprinting of proxy traffic. No classified access required. All of it is within reach of a competent OSINT analyst with the right tooling.
Publishing created the public record that enabled action
Security professionals debate whether to publish threat intelligence or keep it internal. This case is a data point: structured, responsible disclosure to the broader community created the evidentiary foundation for a federal seizure. The researchers who connected NetNut to Popa published. That publication triggered regulatory scrutiny and demonstrably enabled federal action.
Publicly traded companies are open-source targets
Alarum Technologies is listed on NASDAQ. SEC filings, earnings calls, investor presentations, and press releases are all primary-source data. OSINT analysts tracking commercial entities with potential connections to malicious infrastructure should treat corporate disclosures as a first-tier source layer, not an afterthought. That’s where you find the org structure, subsidiary relationships, and financial dependencies that passive DNS alone won’t surface.
What to Do This Week
- Audit proxy vendor contracts. Identify every commercial residential proxy service in use across your organization, red team vendors, and third-party contractors. Request sourcing documentation. If they can’t provide it, that’s your answer.
- Hunt for Popa IOCs. Check DNS, proxy, and endpoint logs against published Popa indicators from the security firms involved in original attribution.
- Brief legal and compliance. If your organization has used NetNut or services with overlapping infrastructure, loop in counsel now — before questions arrive from outside.
- Update residential proxy blocklists. The seizure will generate a public domain and IP list. Add it to your threat intel pipeline as soon as the DOJ publishes.
- Track the court filings. Federal seizure actions produce public court documents. PACER affidavits in support of seizure warrants typically contain the most detailed technical attribution available outside a formal intelligence product — often more granular than vendor blog posts.
The proxy services you use, tolerate, or fail to detect are not neutral infrastructure. The Popa action makes the legal and operational consequences of that neutrality harder to claim ignorance of.
Brian Krebs, “FBI Seizes NetNut Proxy Platform, Popa Botnet,” KrebsOnSecurity, 2026. | IC3 Advisory on Residential Proxy Services, FBI Internet Crime Complaint Center, 2023. | Stanford Internet Observatory, “How Residential Proxy Networks Recruit Devices,” 2024.