Last Update: 09/22/2026 at 11:34 PM EST

FBI Disrupts NetNut Popa Botnet

Coverage from KrebsOnSecurity, Krebs on Security, and others

FBI Disrupts NetNut Popa Botnet topic image

The FBI, Google and other partners seized domains and disabled services associated with NetNut, a residential proxy platform that researchers linked to the Popa botnet.

Popa allegedly used millions of Android TV and similar consumer devices to relay traffic for credential attacks, scraping and other abuse without meaningful user consent. The disruption reduced NetNut’s available proxy pool, but interconnected proxy providers and resellers may allow similar networks to rebuild.

Looking Back
21 Day Timeline
Jun 18Jun 22Jun 26Jun 30Jul 4Jul 8
History
07/21/2026

The update adds concrete execution details about the takedown, including that the FBI seized hundreds of NetNut domains and replaced its website with a seizure notice. It also sharpens the abuse picture by citing Google’s observation of cybercriminal and espionage use of suspected NetNut exit nodes and clarifies the scale of affected devices.

All Articles3 articles
Additional3 articles · CI Score below 45
KrebsOnSecurity
7/2/2026 • Data Collection & Surveillance Practices • General
Krebs on Security / Brian Krebs
6/18/2026 • Data Collection & Surveillance Practices • General
CNET / Joe Hindy
7/8/2026 • Cybersecurity Tech (Privacy-Relevant) • General