
#Op NutCracker: FBI Seizes Domains Used by Netnut’s Residential Proxy Network
Yesterday, the FBI seized key domains of NetNut’s residential proxy network where millions of malicious Popa bots operate, marking a major disruption of one of the largest known residential proxy botnets affecting Smart TVs and other Android connected devices. The take-down operation represents an important milestone in the international effort to identify those responsible and […]

The Uncomfortable Truth Behind Ethical Web Scraping
Qurium has released the findings of a new technical investigation into the “Popa” residential proxy network, a system that transforms consumer devices into residential internet exit nodes and which our previous research linked to infrastructure associated with NetNut and Alarum Technologies. To better understand how the network operates in practice, Qurium joined the Popa network and voluntarily contributed bandwidth as a residential proxy node. Over the course of the investigation, our systems recorded and analyzed more than ten million proxy requests transiting the network.

Qurium traced the global scraping campaign to Popa, a residential proxy network hidden inside consumer devices
Less than a month after documenting a global scraping campaign that drew on more than 1.4 million distributed IP addresses to target public-interest journalism, Qurium Media Foundation, working with independent threat intelligence researchers, including the Nokia Deepfield Emergency Response Team and Synthient, has traced the underlying infrastructure to “Popa”: a residential proxy software family that turns consumer devices into Internet relay nodes.

Exposing Opaque Scraping Infrastructure Targeting Public-Interest Journalism
The investigation documents a large-scale scraping event against the English-language website of Arab Reporters for Investigative Journalism (ARIJ) targeting its library of public-interest investigations and generated a massive volume of automated traffic against the site which received traffic from approx. 1.35 million unique IP addresses, spread across more than 7,300 AS and 223 country codes.

Qurium exposes the residential proxy economy behind the next generation of botnets
Qurium publishes today a new investigation showing how residential proxy networks, Android supply-chain malware, and DDoS botnets are no longer separate problems. They are now part of the same abuse economy. Our research traces how compromised consumer devices, proxy SDKs, grey-market proxy providers, and botnet operators feed one another. KimWolf is not the story. KimWolf is the warning sign.

The show must go on, not!
Last week Europol announced a major international operation that dismantled a cryptocurrency fraud and money-laundering network responsible for laundering more than EUR 700 million. The coordinated action exposed the use of fake investment platforms, social-engineering call centers, cross-border crypto-laundering structures, and, critically, affiliate-marketing systems designed to target victims through deceptive advertising and impersonation of reputable outlets. The operation confirmed that affiliate-marketing infrastructure formed a key pillar of the criminal ecosystem.

Proxy.vn’s hidden Tin-Roof datacenter fueling fake accounts behind the recent attack on iStories.media
Qurium has completed a forensic investigation into the DDoS attacks targeting the Russian investigative media iStories in early November 2025. The investigation links the attacks to Proxy.vn, a Vietnamese proxy network built to exploit residential and mobile internet infrastructure at national scale.

Exposing the Play Field of Catfish Dating
Dating scams have long been a highly profitable “business,” fueled by a vast market and the frequent underreporting of fraud to authorities due to the sensitive nature of the activity. Qurium’s investigation uncovers the full ecosystem of actors involved in these scams and reveals how dating fraud, disinformation campaigns, and financial crime are interconnected — all operating through the same infrastructure and often orchestrated by the same individuals.

Qurium uncovers global takedown attempts targeting its Bifrost mirroring service
Qurium Media Foundation has uncovered multiple takedown requests submitted to Google targeting its Bifrost mirror service, an initiative designed to keep independent journalism accessible in countries with heavy Internet censorship.Qurium’s investigation reveals coordinated international efforts to suppress journalism and erase investigative reporting through legal mechanisms. The takedown demands came from state-linked institutions and reputation management firms operating in Azerbaijan, Pakistan, Russia, and Venezuela.

Proxy provider Biterika connected to state sanctioned research center linked to attack against investigative media
On June 19, Russian independent media outlets IStories and Verstka published a joint investigation detailing how a sprawling network for selling sex with minors was built in Russia and how some of its high-profile clients — such as Russian oligarch and billionaire Oleg Deripaska — had escaped justice. Within hours of publication, both organizations suffered […]
