NetNut, also tracked as Popa, is a large residential proxy network that routes third-party traffic through enrolled home devices worldwide, including smart TVs and streaming boxes. Public reporting and Google Threat Intelligence Group assessments identify NetNut and Popa as the same underlying network. The service has been linked to a commercial proxy ecosystem with reseller relationships that allow multiple brands to sell access to the same underlying device pool, complicating disruption and attribution. The network has been assessed as containing at least 2 million devices and has been used by hundreds of distinct threat clusters, including both cybercriminal and espionage actors, to obscure origin infrastructure and support malicious operations. Observed abuse includes password-guessing activity and use of residential exit nodes to mask operator location. Because enrolled devices can relay external traffic into home networks, the network can also create downstream risk by providing attackers a foothold from which to reach other devices on those networks. NetNut/Popa is associated in the supplied reporting with a proxy provider owned by an Israeli company, Alarum Technologies, although the company has denied that the network is a botnet and has stated that its software is based on user consent. Independent testing cited in the reporting tied commercial NetNut gateway traffic to devices enrolled in Popa. The actor or ecosystem behind NetNut also appears operationally resilient due to its reseller model and overlap with broader proxy and device-abuse ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a separate residential proxy network used to turn devices into conduits for unauthorized traffic via malware-laced SDKs.
A large residential proxy/botnet-style network spread across home devices worldwide, used to route third-party traffic through compromised or covertly enrolled consumer devices and provide anonymity for malicious activity such as password-guessing attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.