FBI Disrupts NetNut Popa Botnet
Coverage from KrebsOnSecurity, Krebs on Security, and others

The FBI, Google and other partners seized domains and disabled services associated with NetNut, a residential proxy platform that researchers linked to the Popa botnet.
Popa allegedly used millions of Android TV and similar consumer devices to relay traffic for credential attacks, scraping and other abuse without meaningful user consent. The disruption reduced NetNut’s available proxy pool, but interconnected proxy providers and resellers may allow similar networks to rebuild.
The update adds concrete execution details about the takedown, including that the FBI seized hundreds of NetNut domains and replaced its website with a seizure notice. It also sharpens the abuse picture by citing Google’s observation of cybercriminal and espionage use of suspected NetNut exit nodes and clarifies the scale of affected devices.
