#Op NutCracker


This page provides a timeline of core events surrounding the Operation NutCracker.

July 2026

[8 July 2026] After recording more than 100M requests routed via Popa, it is nice to see that .xyz remains a top contender of “ethical web scraping”

[7 July 2026] Both netnut[.]io and alarum[.]io domains has been seized by the FBI.

[5 July 2026] Soon after the Alarum announcement, Popa network stop routing traffic (TLV Registration service has been brought down) in all the nodes that we have previously fingerprinted as Popa. During the shutdown, some resellers from China were still active likely connected to Xunjie Electronic Technology Co. or Guangzhou Xunjie Information Technology.

[4 Jul 2026] Alarum announces that as part of their ongoing investigation, and as a precautionary operational measure, the Company has decided to temporarily pause traffic through the relevant network services for several days.

[4 Jul 2026] 8 AM UTC. We keep monitoring the inbound rechability of Popa endpoints from the global Internet from dozens of vintage points. You know what? traffic keeps dropping but mail spam keeps flowing. So much love for Google SMTP2.

9 AM UTC, Balancing domain ninjatech[.]io is being disabled by better Kung Fu.

5 AM UTC netnut[.]io domain finds new name servers

Domain Name: netnut.io
Updated Date: 2026-07-03T05:04:20Z
Name Server: ns1.fbi.seized.gov
Name Server: ns2.fbi.seized.gov

[3 Jul 2026] Alarum Technologies provides update regarding recent law enforcement action, stating that as a result of yesterday’s development, they are currently experiencing disruptions to a portion of its services. Neither Alarum nor NetNut have been formally contacted by the FBI or any other governmental or regulatory authority in connection with this matter.

[3 Jul 2026] Based on analysis of raw data, Qurium estimates that 60% of the infected devices have been disconnected as a result of yesterday’s coordinated disruption operation. The graph below shows the decline of proxy activity in the Popa botnet over the past 24 hours. The decline started around 15:50–16:00 PM UTC with the steepest drop around 16:05–16:25 PM UTC.

[3 Jul 2026] Alarum Technologies issues a Press Release in response to the take-down operation stating “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account.”

[2 Jul 2026] The FBI announces the seizure of NetNut domains (netnut.com, divinetworks.com) and acknowledges the disruption of NetNut infrastructure implemented by Google, Lumen’s Black Lotus Labs, and Shadowserver Foundation.

[2 Jul 2026] Google announces that they in coordination with the FBI, Lumen, and “others” have taken action against the NetNut residential proxy network, also known as Popa. The action goes in line with their objective to dismantle malicious residential proxy networks. Practical actions that were taken include (1) disabled Google accounts and services used by NetNut for malware command and control (C2), (2) shared technical intelligence on NetNut software development kits (SDKs) and backend C2 infrastructure with platform providers, law enforcement, and research firms (3) ensured that Google Play Protect, Android’s built-in security protection, automatically warn users and disable applications known to incorporate NetNut SDKs.

[2 Jul 2026] Brian Krebs (KrebsonSecurity) publishes the article “FBI Seizes NetNut Proxy Platform, Popa Botnet” stating that the FBI has together with industry partners seized hundreds of domains associated with NetNut, “a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]”.

June 2026

[23 Jun 2026] Qurium releases the forensic report “The uncomfortable truth behind 10 million Popa proxy requests“.

[18 Jun 2026] KrebsonSecurity releases the article “‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm“, announcing that researchers from multiple security firms have concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

[18 Jun 2026] Nokia Deepfield Emergency Response Team  releases A free download and a botnet: RoboVPN, Neunative, and the Vo1d/Popa backend

[18 Jun 2026] Synthient releases Popa: From Sourcing to Distribution

[18 Jun 2026] Qurium releases the forensic report “Finding “Popa”: When Your Smart TV Stops Being Yours

[8 Jun 2026] Qurium releases the forensic report “How a Sneaker-Proxy Business Entered the Scraping Industry” linking NetNut to the opaque botnet operations surrounding limited-edition sneaker drops.

[5 June 2026] Bouchodi releases that the SDK of residential proxy provider Bright Data leaked the list of providers running their proxy software including gaming and other mobile and Smart TV applications.

May 2026

[29 May 2026] Qurium released the forensic investigation “Opaque Scrapers Hiding in the Crowd“, linking the scraping event to Alarum Technologies residential proxy service NetNut.

[28 May 2026] Alarum Technologies reports 64% revenue growth to $11.7 million in first quarter of 2026.

[14 May 2026] Arab Reporters for Investigative Journalism (ARIJ.net) is hit by a massive scraping event from 1.35 million unique IP addresses. Qurium, ARIJ’s hosting provider, launches an investigation to identify the actor behind the scraping event.

February 2025

[27 Feb 2025] Research post from Chinese XLABLong Live The Vo1d Botnet: New Variant Hits 1.6 Million TV Globally“, linking “Popa” to the notorious Vo1d botnet in SmartTVs.

[November 2023] Qurium identifies residential proxy provider White Proxies and HostCram, IPXO, Access2.IT, SecureBit, Cloudie, and Heymman Servers as suppliers of IP space behind attacks against Hungarian media.

[August 2023] Qurium releases a one year long research of residential proxies and VPN providers behind denial of service attacks.

2021

[August 2021] Qurium identifies Bright Data infrastructure used to conduct denial of service attacks