Find notable cyber news and cases, enriched with sources, timelines, and signals.

FBI seizes NetNut and Popa botnet domains

Law Enforcement
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The FBI seized hundreds of domains tied to NetNut and the Popa botnet, disrupting infrastructure used for abusive traffic and account-takeover activity. The seizure notice also replaced NetNut’s homepage and named the Internal Revenue Service Criminal Investigation division as a partner in the action. The disruption hit a residential proxy network that had been used to mask malicious traffic and route it through compromised devices.

Related Happenings

Joint operation dismantles First VPN Service (1VPNS)

Law Enforcement
H score33 First: 14.07.2026 11:02 Last: 14.07.2026 11:02 Sources 1

About this happening: European and North American authorities dismantled First VPN Service (1VPNS) in a ransomware-linked takedown, removing infrastructure used to hide attack origins and o...

FBI seizure of NetNut proxy domains

Law Enforcement
H score33 First: 03.07.2026 12:35 Last: 03.07.2026 12:35 Sources 1

About this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...

Popa botnet forcing consumer TV boxes to relay traffic

Malware Activity
H score76 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

How related: The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.

About this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...

Latest development: 03.07.2026 12:35

Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.

Vo1d botnet campaign targeting unofficial Android-based TV boxes

Campaign
H score88 First: 18.06.2026 20:37 Last: 18.06.2026 20:37 Sources 1

About this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...

Latest development: 03.07.2026 12:35

Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.

FBI takedown of Outsider Enterprise phishing service

Law Enforcement
H score63 First: 14.06.2026 17:36 Last: 14.06.2026 17:36 Sources 1

About this happening: The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....

Timeline

  1. 02.07.2026 22:27 1 articles · 13d ago

    Security firms link NetNut to the Popa botnet

    Initial Disclosure

    On June 19, three security firms said NetNut operated a residential proxy network that populated the Popa botnet and distributed software for home devices such as smart TVs and streaming boxes. The software turned those devices into always-on residential proxy nodes that were rented to others for abusive traffic, including mass content scraping, advertising fraud, and account takeover activity.

    Show sources
  2. 02.07.2026 22:27 2 articles · 13d ago

    FBI seizes hundreds of NetNut domains

    Legal Policy Action Update

    On July 2, 2026, the FBI said it worked with industry partners to seize hundreds of domains associated with NetNut, and NetNut’s homepage was replaced with a seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. The action disrupted residential proxy infrastructure tied to the Popa botnet.

    Show sources