The FBI didn’t seize a hacking forum this week. It seized a business. NetNut, a residential proxy platform run by publicly traded Alarum Technologies (NASDAQ: ALAR), had its domains taken down after security researchers tied it to Popa, a botnet quietly running on at least two million home devices whose owners never agreed to any of it. Google’s Threat Intelligence Group, working alongside the FBI and Lumen, says it has already knocked millions of those devices offline. That’s the headline. The real story is what this kind of network does to every cybersecurity control built around trusting an IP address, and how long it ran in plain sight while looking like a legitimate product.

A Legitimate Storefront Hid a Botnet’s Supply Chain
Residential proxy services aren’t inherently illegal. Marketers use them for ad verification, researchers use them to see geo-restricted content, and plenty of companies buy access legitimately. The problem is where the IP addresses come from. NetNut and services like it acquire “exit nodes” through SDKs bundled into free apps, cracked software, and other installs that quietly turn a device into a relay for someone else’s traffic. Multiply that across free VPN apps, sketchy Android APKs, and abandoned IoT firmware, and you get a pool of millions of devices that route strangers’ traffic through a homeowner’s router without anyone in that house knowing.
That’s what investigators say happened with Popa. The botnet supplied the exit nodes; NetNut sold access to them as a commercial product, listed on a stock exchange, marketed with a sales team and a support desk. It’s the same laundering pattern that’s shown up in prior proxy takedowns: dirty infrastructure gets a clean interface, invoices, and a terms-of-service page, and buyers downstream rarely ask hard questions about where the IPs actually come from.
Every IP-Based Defense Just Got Weaker
Here’s why this matters more than a typical botnet bust. Most threat detection still leans heavily on IP reputation. Rate limiting, geofencing, brute-force lockouts, even a lot of fraud scoring, all assume that traffic from a residential IP in Ohio probably belongs to a person in Ohio. Residential proxy networks exist specifically to break that assumption. When a credential-stuffing run or a password-spray campaign gets routed through two million real home connections instead of a cluster of cloud servers, every login attempt looks like it’s coming from a different ordinary user in a different ordinary city. Your firewall doesn’t blink. Your brute-force protection doesn’t trigger, because no single IP ever crosses the threshold.
This is exactly the kind of infrastructure that groups running large-scale account takeover and initial-access operations buy on purpose. Extortion-driven crews have made a habit of blending in with normal user traffic during credential attacks precisely so IP-based threat detection never fires.
The retailer’s security team removed the attackers from its network before any ransom was paid. The company still incurred at least $2 million in losses from business disruption, incident response, and recovery.
That figure, from a separate case tied to a Scattered Spider suspect recently extradited to the US, isn’t about proxies specifically. It’s a reminder of what “detected in time” actually costs even when it works. Now imagine the same attack chain, except the login attempts were laundered through a residential proxy network the whole time and detection took days instead of hours. Defense in depth stops being a nice phrase and starts being the only thing standing between a blocked login and a six-figure incident.
Takedowns Buy Time. They Don’t Buy Immunity
Seizing NetNut’s domains and degrading Popa’s device pool is a real win, but residential proxy markets regenerate fast. New brands, new SDKs, new “free” apps recruiting new devices. Security hardening against this category of threat has to assume the supply will come back under a different name within months. A few things are worth doing now, not after the next network shows up:
- Stop treating IP reputation as a primary trust signal. Layer in device fingerprinting, session behavior, and login velocity per account rather than per address.
- Flag and challenge traffic from known residential proxy and VPN ASN ranges on sensitive endpoints like login, password reset, and checkout, even though it will produce false positives.
- Audit your own IoT and router fleet, home or office, for unrecognized outbound connections and unexpected background processes; this is how devices get recruited in the first place.
- Tighten brute-force lockouts to count failed attempts per account across all source IPs, not just per address, so a distributed low-and-slow attack still trips a threshold.
- Require phishing-resistant MFA everywhere credential stuffing could land, so a successful password guess still doesn’t produce a usable session.
- Feed proxy and botnet exit-node intelligence into your detection stack on a recurring basis; these lists go stale within weeks.
None of this requires new budget for exotic tooling. It requires accepting that the address a request comes from tells you less than it used to, and building incident response playbooks that assume attackers are already inside the noise floor of normal traffic. Apple’s decision to compress its own patch cycles because AI is shortening the gap between disclosure and exploitation points at the same underlying shift: the old signals defenders relied on, patch windows, IP reputation, geographic anomalies, are all eroding at once. Proxy botnets like Popa are just the version of that erosion aimed straight at your login page.
Sources
- FBI Seizes NetNut Proxy Platform, Popa Botnet
- Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices
- Scattered Spider suspect extradited over $8 million ransom scheme
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
