:

FBI SEIZES NETNUT PROXY PLATFORM, POPA BOTNET

SECURITY DESK2 MIN READ
THU, JUL 2, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The FBI has seized hundreds of domains belonging to NetNut, a residential proxy service operated by Israeli firm Alarum Technologies, following discoveries linking the platform to the Popa botnet comprising millions of compromised devices.

The action represents a coordinated effort between federal law enforcement and industry partners to dismantle infrastructure connected to malicious activity. NetNut operated as a proxy service offering users the ability to route internet traffic through residential IP addresses, a capability that can mask user identity and location. Security researchers identified NetNut's connection to the Popa botnet roughly two weeks before the seizure, according to findings published by KrebsOnSecurity. The botnet comprises at least two million compromised devices infected with malicious software. Alarums Technologies, the parent company of NetNut, is publicly traded on NASDAQ under ticker symbol ALAR. The seizure marks a significant enforcement action against a company operating in the proxy service sector, which has faced increasing scrutiny over potential misuse for cybercrime, fraud, and evading security systems. The FBI's action underscores ongoing tensions between legitimate proxy service operations and their exploitation by malicious actors. Residential proxies route traffic through actual home internet connections, making detection and blocking more difficult than traditional data center proxies. The seizure included hundreds of domains, suggesting NetNut maintained extensive infrastructure to support its operations. The takedown likely disrupts services for both legitimate and illicit users relying on the platform. This enforcement action follows a broader pattern of law enforcement targeting proxy services and botnet infrastructure. Earlier cases have demonstrated the challenges in distinguishing between legitimate privacy tools and platforms facilitating criminal activity.

■ SOURCES

Krebs on Security

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.

2H AGOSecurity Desk

More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.

2H AGOIndustry Desk

A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.

4H AGOIndustry Desk

Hacking group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. Security researchers confirmed the breach included detailed customer, booking, and travel records.

7H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.