Popa, also tracked as NetNut, is a large residential proxy network spread across home devices worldwide, including smart TVs and streaming boxes. Google Threat Intelligence Group stated that the network contained at least 2 million devices and that, in one week in June, 316 distinct threat clusters used suspected NetNut exit nodes, including cybercriminal and espionage groups. Google said these exit nodes were used to hide operators’ real locations and conduct activity such as password-guessing attacks, and warned that routing third-party traffic through enrolled home devices can expose victims’ home networks to unauthorized traffic and potential attacker footholds. Google said it significantly degraded the network with support from the FBI, Lumen, and other partners, reducing its usable device pool by millions, but assessed that durable disruption is difficult because of a reseller model. Google has high confidence that many popular proxy brands are reselling the same underlying NetNut device pool and warned defenders to watch for NetNut-linked traffic resurfacing under reseller brands. Public research from Qurium, Synthient, Nokia Deepfield, and Spur tied Popa to NetNut, and Google said its own intelligence aligns with that reporting. NetNut is described in the content as a proxy provider owned by Alarum Technologies, an Israeli public company, although Alarum rejected the characterization of NetNut as a botnet and said its software is based on consented bandwidth sharing. Synthient reported that none of the more than 20 apps it examined displayed a user consent prompt. Known alias: Popa.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a separate residential proxy network used to turn devices into conduits for unauthorized traffic via malware-laced SDKs.
A large residential proxy/botnet-style network spread across home devices worldwide, used to route third-party traffic through compromised or covertly enrolled consumer devices and provide anonymity for malicious activity such as password-guessing attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.