Home Droven.io FBI Shuts Down NetNut Proxy Network
Droven.io

FBI Shuts Down NetNut Proxy Network

Share
Popa Botne
Share

A major international law enforcement operation has recently disrupted a massive global cyber threat network. Specifically, the FBI and Google worked in close coordination on this project. Together, they successfully shut down NetNut, which operated as one of the world’s largest commercial proxy networks.

Furthermore, security teams often track this specific network under the name “Popa botnet.” The dangerous network secretly took control of more than 2 million consumer devices worldwide. Consequently, it turned ordinary home electronics into traffic-routing relays for hackers and state spies.

The Partners Who Stopped the Network

Fortunately, many distinct groups joined forces to stop this massive security threat. This impressive coalition included the FBI and Google’s Threat Intelligence Group. Additionally, they worked alongside Lumen Technologies and the Shadowserver Foundation. The United States Internal Revenue Service also assisted with the complex financial investigation.

Ultimately, these groups took down the digital infrastructure that powered the proxy service. At the same time, they seized hundreds of website domains used by the threat actors.

How the Popa Botnet Hijacked Smart Devices

To understand the threat, we must examine how the NetNut proxy service relied entirely on the Popa botnet. This malicious botnet functioned as a hidden communications layer. For instance, it worked by embedding deceptive software kits into cheap, off-brand Android smart TVs. It also infected streaming media boxes and unofficial video applications.

As soon as consumers plugged these devices in, their home internet connections were quietly rented out. Cybercriminals then used these home internet setups as proxy exit nodes. Therefore, this clever trick allowed bad internet traffic to look like regular household traffic.

Because the resulting traffic came from real homes, standard security filters could not easily block it. Thus, the setup helped cybercriminals hide their digital tracks from security analysts.

In addition, a report from Google showed how bad the problem had become. For example, in just one week, at least 316 distinct hacker groups utilized NetNut. They used the network to run aggressive password attacks and steal credentials. Similarly, they used it for advertising fraud and scraping sensitive data.

The Link to a Real Commercial Business

Hidden, underground criminal groups run most botnets. However, official reports show that NetNut links directly to a real commercial business. That business is Alarum Technologies Limited. Notably, it is a publicly traded company listed on the NASDAQ.

Security researchers eventually found direct links between the company’s bosses and the original software developers. Although the company always advertised its software as a legal tool for sharing internet bandwidth, technical reviews revealed a different reality. Specifically, these reviews proved that users never gave real consent. Moreover, the host applications never warned users about the background activity.

Right after the FBI seized the web domains, Alarum issued an official statement. The company stated that it takes the matter very seriously. Meanwhile, it promised to cooperate fully with law enforcement. It also promised to investigate how its infrastructure was misused.

Separately, Google researchers noted that NetNut had a large reseller program. This program easily allowed other brands to hide the NetNut name. Because of this practice, many other proxy brands are actually using the NetNut network. Furthermore, public reports link NetNut to dangerous computer viruses, such as the Mirai botnet.

Google and the FBI Deploy Strong Clean-Up Tools

To prevent the network from being rebuilt, Google and the FBI took swift action. For example, Google deactivated all accounts that NetNut used to control infected devices. They also updated Google Play Protect. As a result, this application now warns Android users about the dangerous software. Google also blocked the specific apps that carried the bad software kits.

Therefore, Google believes these actions have severely damaged NetNut’s business operations. The pool of available hijacked devices has dropped by millions. Interestingly, this action follows the successful shutdown of the IPIDEA proxy network earlier this year.

Understanding the Domain Takedown Confusion

Initially, the first phase of the operation caused some confusion online. People noticed that the FBI seizure banner appeared on netnut.com. However, the company’s other website, netnut.io, stayed active for a short time.

Consequently, some people thought law enforcement targeted the wrong web domain. Security experts quickly cleared up the confusion. They explained that both websites are part of the same criminal case.

Of course, taking down a domain can take time due to different international laws. However, the main control servers were successfully dismantled. This success means the network can no longer function properly.

The Lessons for Global Corporate Governance

This major takedown clearly shows that AI transformation is a governance problem. For this reason, companies must monitor their digital boundaries closely. They must protect their networks from hidden software kits. Otherwise, connecting untrusted devices can open up major security gaps.

To keep your systems safe, your IT teams must track external network threats. For example, regularly checking the latest droven.io cybersecurity updates helps engineers protect company data. It ensures your business avoids bad proxy connections.

Furthermore, you should protect your business from automated data scraping tools. To learn how to build secure internal systems, review our guide to droven.io AI automation tools. Using safe, verified networks keeps your company data protected.

Final Thoughts

The NetNut shutdown is a huge win for global cybersecurity. It proves that tech companies and law enforcement can stop massive digital threats. By cleaning up infected home devices and seizing domains, they made the internet safer for everyone.

Always keep your smart devices up to date to protect your home network from hidden botnets. For more information on shifting tech laws, check out our guide to Japan AI policy news today.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Extensible Authentication Protocol
Droven.io

EAP Explained: How Extensible Authentication Protocol Works

Modern network infrastructure requires robust access control long before an endpoint receives...

mobile security threats
Droven.io

Top 4 Mobile Security Threats Facing Enterprises

Mobile devices now serve as primary productivity tools across the enterprise landscape....

Corporate Owned Personally Enabled
Droven.io

COPE Explained: Corporate-Owned, Personally Enabled

Managing mobile endpoints requires balancing enterprise security with user convenience. To achieve...

BYOD
Droven.io

BYOD Policy: Protect Company Data and Employee Privacy

The traditional boundaries of corporate IT have completely vanished. Employees expect the...

The Ethical Hacker delivers insights on ethical tech, AI, Web3, autonomous vehicles, and responsible innovation.

Stay Connected

Subscribe to get the latest ethical tech news and insights straight to your inbox.

    Copyright 2026 The Ethical Hacker. All rights reserved.