Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

FBI Seizes NetNut Proxy Platform, Popa Botnet

FBI seized domains of NetNut, a residential proxy service run by Israel-listed Alarum Technologies, and the associated Popa botnet—highlighting how legitimate-seeming proxy infrastructure enables credential-stuffing and fraud at scale.

Summary written by editorial AI · Source link below

Filed by Krebs on Security1 min readRead at source ↗

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software wi

Editorial Analysis

Why it matters

Enterprises using third-party proxy or traffic-analytics services should verify that providers are not built on compromised residential endpoints, which can taint data and expose legal liability.

What to do

Audit any contracted proxy or web-scraping services against the published NetNut IOC list and verify that no corporate traffic routes through compromised residential nodes.

Board brief

A publicly traded proxy provider was seized by the FBI for operating on millions of infected devices—third-party vendor due diligence must cover infrastructure provenance.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Krebs on Security

External link — opens at Krebs on Security in a new tab.

§
Continue with

More from the Threat Intel Desk