Threat Intelligence

The Popa Botnet Was Hiding in Plain Sight

The Popa Botnet Was Hiding in Plain Sight

Howard University never signed up to be a proxy provider. But for months, anyone with five dollars in crypto and a burner email address could route their internet traffic through the university’s entire /16 IP space, and nobody on campus had any idea it was happening. 

On July 2, 2026, the FBI and IRS Criminal Investigation division seized hundreds of domains operated by NetNut, a residential proxy service owned by Alarum Technologies (NASDAQ: ALAR), an Israeli company traded on the NASDAQ. The seizure notice replaced NetNut’s homepage. Within a week, Alarum’s stock had dropped 67 percent. 

The takedown was the culmination of four years of forensic work by at least six independent research teams. It was also the second time in six months that the FBI and Google had teamed up to tear down a major residential proxy network. In January, the target was IPIDEA, a Chinese-operated service with a pool of nearly 10 million compromised devices. When IPIDEA went down, its customers migrated. NetNut absorbed a significant share. 

The Botnet That Wasn’t Supposed to Be a Botnet 

NetNut’s parent company denies the botnet characterization. Alarum’s legal counsel described it as “a legitimate commercial proxy network” with “policies, procedures, and technological measures designed to promote lawful and responsible use.” The company maintains it performs KYC checks on customers and monitors for misuse. 

The evidence tells a different story. Synthient, the proxy-tracking firm, ran a controlled test on June 17, 2026. It issued a request into NetNut’s commercial gateway. The request egressed from a device running the Popa SDK with the path `/NETNUT_EXT_TRAFFIC_FROM_PROXY`. No third-party traffic was involved. The test proved, in Synthient’s words, that “Popa actively continues to be used by NetNut as part of their proxy pool.” 

The Popa SDK itself is a multi-variant piece of proxyware that has been in continuous development since at least 2020. Synthient documented four distinct code families: Moneytiser (December 2020), Popa (March 2022), Loopop (November 2023), and Neupop, a C++ native variant from February 2026 designed to evade Java-level detection. Across more than 20 publisher apps analyzed, not a single one displayed a consent prompt to users before enrolling their device as a proxy exit node. 

The SDK’s distribution model is simple. App developers bundle it into free streaming apps, IPTV utilities, screensavers, and simple games. When the user opens the app, the SDK phones home to `sdk.netnut.io`, registers the device, and starts relaying traffic. The user sees a free way to watch movies. The proxy network sees a fresh residential IP address to sell at USD 3.50 to USD 15.00 per gigabyte. 

The Smart TV’s Second Job 

If you own an LG or Samsung smart TV and have installed apps from the manufacturer’s official store, there is a measurable chance your television is currently routing third-party internet traffic. 

Spur examined both app stores in June 2026. Forty-two percent of apps on LG’s webOS platform included residential proxy SDKs. More than 25 percent of Samsung Tizen apps did the same. These are not obscure sideloaded packages. They are games, utilities, and streaming tools available through the official storefronts, using fine-print disclosures navigated by TV remote as their consent mechanism. 

Amazon and Roku have both banned proxy SDKs from their platforms. As of July 2026, LG announced it would follow suit. Samsung has not. 

The corporate exposure from this is not theoretical. A smart TV in a meeting room, connected to the corporate LAN and running a free game installed by a facilities contractor, provides a threat actor with egress from inside the organization’s perimeter. VPN controls, network access controls, and zero-trust architecture cannot see it because the traffic originates from a device those controls do not manage. 

The ISP Problem Nobody Is Watching 

The consumer SDK story is bad enough. The ISP-level integration is worse. 

Spur documented how NetNut, through its partner DiviNetworks, recruits network operators to install GRE tunnel configurations on their border routers. The configuration is minimal: a few lines on a MikroTik, Juniper, or Cisco device. A GRE tunnel connects the partner’s edge router to a DiviNetworks termination point. Policy-based routing redirects a small slice of traffic through that tunnel. From NetNut’s perspective, every IP address in the partner’s announced prefix becomes commercial proxy egress. From the partner’s perspective, a revenue stream appears: DiviNetworks advertises USD $13,208 per month for a US /16 at 1 GB per IP. 

When Spur routed 80,000 test requests through NetNut’s static residential proxy pool, roughly 21 percent egressed through Howard University’s `138.238.0.0/16` space. Every announced subnet was affected, yielding 15,000 distinct Howard IP addresses as proxy exits. This was not a cluster of compromised endpoints. This was the entire prefix, commercialized. 

Nobody at Howard opted in. Nobody installed anything. The change lived on the edge router, invisible to endpoint security and invisible to the people who use the network every day. 

The mechanism matters because it exposes a gap in the mental model most security teams operate under. When abuse reports, fraud flags, or law enforcement inquiries land on your ASN, the instinct is to look for compromised hosts. If the compromise lives at the router level and was installed by a managed service provider or a complicit insider collecting monthly payouts, no host investigation will find it. 

What the Takedown Achieved (and What It Didn’t) 

Google GTIG estimates the disruption reduced NetNut’s available device pool by millions. The company disabled Google accounts used for Popa C2, shared SDK intelligence with platform providers and law enforcement, and pushed Google Play Protect warnings to users with infected apps. 

The immediate operational impact was real. Benjamin Brundage, founder of Synthient, described it as “a big impact” for the cybercrime community, which was already reeling from the IPIDEA takedown in January. NetNut had gained significant popularity after IPIDEA’s decline. Its removal from the market eliminates a major source of residential proxy capacity. 

But the proxy ecosystem adapts. Google itself warned in its disruption announcement that “when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.” IPIDEA did exactly this after January. NetNut’s resellers will almost certainly do the same now. 

The underlying economics have not changed. Content scraping at AI-training scale needs residential IPs. Account takeover campaigns need residential IPs. Advertising fraud needs residential IPs. State-aligned espionage groups need residential IPs to mask their operational origin. As long as that demand exists, supply will reorganize to meet it. Each takedown redistributes capacity rather than reducing it. 

What Defenders Should Do Right Now 

The takedown has created a window. The infrastructure that supported 2 million compromised devices is offline. The reseller ecosystem is scrambling. The window will not stay open long. 

First, check whether your organization’s public IP space appears in proxy egress data. Synthient operates a public check service. Spur’s Context API provides similar capability. If your prefixes are showing up as proxy exits, you have a router-level integration problem, not a host-level compromise problem. 

Second, audit your border router configurations. Look for GRE tunnels terminating at `divinetworks.com` subdomains. Look for policy-based routing rules that redirect traffic to unexpected VMs or tunnel endpoints. If a managed service provider administers your edge routers, ask them directly whether any DiviNetworks or similar integration exists. 

Third, inventory every smart TV on your corporate network. Give them a dedicated VLAN with outbound access restricted to known streaming and conferencing destinations only. They are not managed endpoints. Treat them accordingly. 

Fourth, block the known NetNut/Popa C2 infrastructure at your DNS and firewall layers. Synthient, Google GTIG, Qurium, and Spur have all published IOCs. Feed them into your blocklists. Monitor for connections to newly registered domains matching proxy infrastructure patterns. 

Analyst Assessment

The NetNut takedown is the most significant residential proxy disruption of 2026, but it is a tactical victory in a structural fight. The proxy economy will reorganise. Defenders who use this window to implement durable network-level egress controls, border router audits, and smart TV network segmentation will be materially better positioned when the next network reaches the same scale.