you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 18 min ago 255 onions tracked
home / news / security
27 August 2026 security 5 min read

FBI seizes NetNut proxy platform: the Popa botnet behind it

On July 2, 2026, visitors to NetNut's web properties started seeing something unfamiliar: a federal seizure banner. The FBI, working with IRS Criminal Investigation, had taken control of hundreds of domains tied to one of the largest residential proxy platforms in the world.

NetNut was not some fly-by-night carding shop. It operated under Alarum Technologies (NASDAQ: ALAR), an Israeli company that cooperated with investigators after the seizure. That corporate pedigree is what makes the case interesting, because underneath the polished enterprise sales pitch sat a botnet of at least two million compromised smart TVs and streaming boxes.

The Popa botnet: your smart TV as someone else's exit node

The node base powering NetNut came to be known as the Popa botnet. Instead of renting bandwidth from consenting users through SDKs and reward apps, the operators compromised consumer devices — televisions and streaming sticks running Android-derived firmware — and quietly turned them into relay points for other people's traffic. From the owner's perspective, nothing obvious changed. The TV kept streaming. From the network's perspective, millions of home connections in ordinary residential IP ranges became available as exits. Traffic leaving a Popa node looked like it came from a household, not a data center, which is exactly why fraudsters, scrapers, and credential-stuffing crews paid for access. This is the core commodity of the residential proxy market: clean-looking exit layers. Anyone who has run infrastructure on Tor understands the dynamic from the other side. Exit nodes get painted with everything that passes through them, and entire address ranges earn reputations that have little to do with the operator. Residential proxies exist to launder reputation — to borrow the trust attached to a suburban cable connection.

Google counted 316 threat-actor clusters in one week

How much actual malicious traffic flowed through these exits? Google's Threat Intelligence Group put a number on it. In a single week of June 2026, GTIG observed 316 distinct threat-actor clusters using suspected NetNut exit nodes. Not 316 attacks — 316 separate actor groups, in seven days, all leaning on one provider's infrastructure. That scale reframes the seizure. Taking down NetNut did not just disrupt a vendor; it pulled a shared utility out from under hundreds of concurrent operations at once. Researchers have compared residential proxy networks to the bulletproof-hosting ecosystems of earlier eras: individually replaceable, but collectively load-bearing for a huge slice of online crime. The seizure also continues a pattern. Law enforcement has spent recent years working through the proxy stack — 911 S5, Bright Data controversies, various VPN-linked operations — and each takedown reveals the same architecture: a legitimate-sounding business on top, an involuntary device fleet below.

The follow-on: LG bans proxy SDKs from webOS apps

The NetNut action had immediate consequences beyond the banner pages. LG announced it would suspend apps on its webOS store found embedding residential-proxy SDKs — software libraries that monetize a TV's internet connection by selling its bandwidth. By Spur's analysis, such SDKs were present in more than 42 percent of apps in the LG store, meaning nearly half the catalog was potentially participating in bandwidth resale. That number deserves a moment of reflection. Consent-based proxy SDKs are the legal cousin of what Popa did by force, and they had spread through app stores precisely because TV apps are cheaply made and the payouts are easy money for developers. A user installing a weather widget was, in many cases, also installing an exit node. For the full reporting on the seizure itself and Alarum's cooperation with authorities, see Brian Krebs' original coverage (KrebsOnSecurity).

What this means for Tor users

If you rely on onion services or the wider Tor ecosystem, the NetNut case is worth reading closely for three reasons. First, it confirms that the exit layer is a contested commodity. Adversaries who need clean egress will not stop because one provider fell; they will migrate to the next botnet, the next consent-farm, or — relevant here — they will abuse Tor exits themselves, which is why exit-node reputation remains such a persistent operational headache. Second, it shows law enforcement getting comfortable with infrastructure seizures that span hundreds of domains simultaneously, coordinated across agencies and jurisdictions. The same playbook that took down darknet markets now applies to networking companies with stock tickers. Anonymization infrastructure is not exempt; arguably it is a priority target. Third, the device fleet problem is not going away. Millions of smart TVs made fine botnet nodes because nobody patches them and nobody watches their traffic. The same devices sitting on home networks are adjacent to the residential IPs that Tor bridges, snowflake proxies, and similar systems depend on. When the neighborhood gets owned, the neighborhood gets owned. Keep in mind that every seizure like this one reshuffles where hostile traffic comes from next. For background on how infrastructure pressure has historically shaped anonymity networks, read our piece on the history of DDoS on Tor. The Popa botnet is dismantled, NetNut is offline, and 42 percent of an app store got audited overnight. The demand for clean exits did not disappear with them. It never does — it just moves, and the next move may land somewhere much closer to the network you use every day.

more notes

all news ›