The Federal Bureau of Investigation (FBI), in coordination with international law enforcement and a coalition of private-sector technology partners, has successfully executed a major operation to dismantle the infrastructure of NetNut, a prominent residential proxy service. The operation resulted in the seizure of hundreds of domains associated with the service, which is operated by Alarum Technologies, a publicly traded Israeli firm listed on the NASDAQ under the ticker ALAR. This law enforcement action marks a significant escalation in the global effort to combat the abuse of residential proxy networks by cybercriminals and state-sponsored threat actors.

The seizure of NetNut’s digital infrastructure comes approximately two weeks after a series of investigative reports by cybersecurity firms, including findings published by KrebsOnSecurity, established a direct link between NetNut and the "Popa" botnet. The Popa botnet is a massive network comprising at least two million compromised devices, including smart TVs, streaming boxes, and other Internet of Things (IoT) hardware. These devices were reportedly infected with malicious software, often without the owners’ knowledge or consent, to serve as "nodes" for relaying internet traffic.

The Intersection of Residential Proxies and Cybercrime

Residential proxy services like NetNut provide users with the ability to route their internet traffic through the IP addresses of home-based devices. While there are legitimate use cases for such services—such as localized software testing or market research—the industry has long been criticized for its lack of transparency and its role in facilitating illicit activity. Because traffic routed through a residential proxy appears to originate from a legitimate home user, it is significantly harder for automated security systems to detect and block.

According to the Google Threat Intelligence Group (GTIG), which played a pivotal role in the investigation, NetNut’s infrastructure was heavily utilized by a diverse array of bad actors. In a single week during June 2026, Google researchers observed 316 distinct clusters of threat actors using NetNut exit nodes. These actors ranged from traditional cybercriminals engaged in financial fraud to sophisticated espionage groups seeking to mask their origins while infiltrating sensitive environments.

The GTIG report highlighted that these bad actors utilized NetNut to conduct password spray attacks, access victim environments, and obfuscate the source of their malicious traffic. Furthermore, when a consumer device is converted into an exit node, it creates a security vacuum within the victim’s home. Unauthorized traffic passing through the device can allow attackers to gain visibility into the local network, potentially exposing other private devices, such as personal computers and smart home controllers, to further exploitation.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Chronology of the NetNut Disruption

The downfall of NetNut is the result of a multi-year effort to map the residential proxy ecosystem and identify the technical overlaps between commercial services and botnet operations.

  • November 2025: Security researchers begin documenting a surge in "sketchy" Android TV streaming boxes sold on major e-commerce platforms. These devices were found to come pre-installed with proxy software or required "updates" that bundled malicious SDKs.
  • January 2026: Synthient, a proxy tracking service, reveals the existence of the "Kimwolf" botnet. The investigation shows how cybercriminals were tunneling through proxy connections to infect Android-based devices behind home firewalls, creating one of the world’s largest Distributed Denial-of-Service (DDoS) networks.
  • Early 2026: A major law enforcement action, led by Google and federal authorities, disrupts IPIDEA, then the primary competitor to NetNut. In the vacuum left by IPIDEA, NetNut experiences a surge in popularity among both legitimate resellers and cybercriminal entities.
  • June 19, 2026: Three independent security firms release coordinated findings linking NetNut to the Popa botnet. The reports demonstrate that NetNut’s "residential nodes" were actually compromised devices within the Popa network.
  • June 2026: Google begins disabling accounts and services used by NetNut for malware command and control, while sharing technical intelligence with law enforcement and other industry partners.
  • July 2026: The FBI and the Internal Revenue Service Criminal Investigation (IRS-CI) division officially seize hundreds of NetNut-associated domains. Visitors to the NetNut homepage are greeted with a seizure banner detailing the multi-agency operation.

Industry and Corporate Reactions

The fallout from the FBI action was immediate for Alarum Technologies. Following the domain seizures, the company’s stock price plummeted, trading as low as $2.62 a share—a staggering 67 percent decline within a single week.

Omer Weiss, legal counsel for Alarum Technologies, issued a statement following the seizure, asserting that the company is cooperating with federal authorities. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. Despite this, the seizure of the company’s primary website, alarum.io, suggests that investigators are looking closely at the corporate entity’s role in the operation of the proxy network.

Benjamin Brundage, the founder of Synthient, noted that the impact of this takedown would be felt across the entire cybercrime landscape. "NetNut has been incredibly common among resellers," Brundage explained. "They were on par with IPIDEA in terms of daily traffic, quality, and size. This disruption will significantly disadvantage threat actors who relied on NetNut’s stability to conduct their operations."

Technical Analysis: The SDK Threat and Home Network Security

The primary vector for the Popa botnet’s expansion was the use of Software Development Kits (SDKs) embedded in seemingly harmless applications. These SDKs were often bundled into unofficial streaming apps or third-party app stores. When a user installed an app to watch pirated content or access specialized services, the SDK would quietly enroll the device into the NetNut network.

A report by the proxy tracking company Spur recently underscored the scale of this problem. Their research found that 42 percent of apps available for the webOS operating system (used on LG smart TVs) and more than 25 percent of apps for Samsung’s Tizen operating system contained residential proxy SDKs. These components effectively turn a consumer’s television into an always-on proxy node that is rented out to the highest bidder.

FBI Seizes NetNut Proxy Platform, Popa Botnet

The technical implications are severe. Because these devices are "always on," they provide a persistent presence for attackers. Furthermore, the use of residential IPs bypasses the reputation-based filtering that many organizations use to block traffic from known data centers or suspicious VPNs. By blending in with the traffic of everyday households, attackers can conduct large-scale scraping or fraud operations with a much lower risk of detection.

Consumer Protection and Future Implications

The FBI’s action against NetNut is a victory for cybersecurity, but experts warn that the battle against malicious residential proxies is far from over. Google’s Threat Intelligence Group noted that the residential proxy ecosystem is highly fluid. When one provider is taken down, others often fill the gap by buying capacity from competitors or "white-labeling" other botnets to maintain their service levels.

"While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient," the GTIG report stated. "Proxy operators often begin buying capacity from their competitors, effectively becoming a reseller."

For consumers, the takeaway is a renewed focus on hardware and software integrity. Cybersecurity experts and federal agencies recommend several steps to avoid becoming an unwitting participant in a botnet:

  1. Stick to Reputable Brands: Consumers are advised to purchase TV streaming boxes and smart TVs from well-known manufacturers with a track record of security updates.
  2. Verify Play Protect Certification: For Android-based devices, users should ensure the device is Google Play Protect certified. Devices that run unofficial or "modified" versions of Android are significantly more likely to contain pre-installed malware or proxy SDKs.
  3. Audit App Permissions: Be judicious about the apps installed on smart TVs. If an app from an unknown developer asks for extensive network permissions, it may be a proxy node in disguise.
  4. Network Monitoring: Advanced users should monitor their home network traffic for unusual outbound activity, particularly from IoT devices that should not be communicating with hundreds of external IP addresses.

The dismantling of NetNut and the disruption of the Popa botnet represent a significant milestone in the fight against the "commercialization" of botnets. By targeting the financial and technical infrastructure of these services, law enforcement and industry partners are making it increasingly difficult and expensive for cybercriminals to hide their tracks. However, as the digital landscape continues to evolve, the vigilance of both the private sector and the individual consumer remains the most effective defense against the growing threat of residential proxy abuse.

By Nana Wu

Leave a Reply

Your email address will not be published. Required fields are marked *