In a significant international cybersecurity operation, the Federal Bureau of Investigation (FBI), in collaboration with key industry partners, announced today the successful seizure of hundreds of internet domains associated with NetNut, a prominent residential proxy service. This decisive action directly targets the infrastructure of the Popa botnet, a vast network estimated to comprise at least two million compromised devices, which have been surreptitiously enlisted through malicious software, often without the knowledge or consent of their owners. NetNut, operated by the publicly-traded Israeli company Alarum Technologies (NASDAQ: ALAR), had become a critical component in the illicit activities of cybercriminals worldwide, providing an anonymizing layer for a wide array of nefarious operations. The takedown follows a period of intense scrutiny and public revelations, most notably from cybersecurity journalist Brian Krebs of KrebsOnSecurity, who, roughly two weeks prior to the seizure, published detailed findings from multiple security firms connecting NetNut directly to the Popa botnet’s widespread compromise.
Understanding the Threat: Residential Proxies and the Popa Botnet
At its core, a residential proxy service like NetNut functions by routing internet traffic through IP addresses assigned to legitimate residential internet service providers (ISPs). Unlike traditional data center proxies, which are easily identifiable and blockable, residential proxies offer a veneer of legitimacy, making it exceedingly difficult for target websites or security systems to distinguish between genuine user traffic and malicious automated activity. This inherent characteristic makes them invaluable to cybercriminals seeking to evade detection and bypass security measures such as IP-based blocking and rate limiting. NetNut capitalized on this by covertly installing software, often disguised or embedded within applications, on unsuspecting consumer devices, effectively transforming them into "always-on" proxy nodes. These devices, commonly found in homes, include smart televisions, low-cost streaming boxes, and potentially other internet-of-things (IoT) gadgets that lack robust security protocols. The owners of these devices were largely unaware that their internet connection and device resources were being leased out, often to facilitate abusive and intrusive internet traffic. The nature of this traffic spanned a broad spectrum of illicit activities, from mass content scraping and web harvesting, which can be used for competitive intelligence or data theft, to sophisticated advertising fraud schemes designed to siphon ad revenue, and account takeover attempts that exploit stolen credentials on a massive scale.
The Popa botnet represents the dark side of this residential proxy model. It is not merely a network of legitimate users sharing bandwidth for legitimate purposes; rather, it is a collection of devices compromised by malicious software, turning them into unwilling participants in a global criminal enterprise. This malware, often bundled with seemingly innocuous third-party applications or embedded within the firmware of low-cost, unbranded streaming devices prevalent in certain markets, operates in the background, consuming bandwidth, depleting device resources, and providing proxy services to NetNut’s clientele. The sheer scale of the Popa botnet, with its estimated two million compromised devices spread across various geographies, underscores the pervasive nature of this threat and the significant reach of NetNut’s operations. The victims, ordinary internet users, often experience subtle but impactful consequences such as degraded network performance, increased data usage, and, more alarmingly, the potential exposure of their home networks to further cyber threats as malicious traffic flows through their devices, creating potential vulnerabilities for other connected systems.
A Coordinated Response: The Path to Takedown
The dismantling of NetNut and disruption of the Popa botnet was the culmination of meticulous research, extensive intelligence sharing, and coordinated law enforcement action across international borders. The timeline leading to the seizure highlights the critical role of independent security researchers and industry collaboration in uncovering and addressing sophisticated cyber threats:
- January 2026 (Pre-Contextual Action): Earlier in the year, Google initiated significant legal actions and technical disruptions, targeting the infrastructure of IPIDEA, which at the time was considered NetNut’s largest competitor in the residential proxy market. This precedent set the stage for further actions against similar illicit services and likely contributed to NetNut’s subsequent surge in popularity and market share within the cybercriminal underworld as threat actors sought alternative solutions.
- June 19, 2026 (Public Exposure): Multiple independent security firms simultaneously published their detailed findings, drawing a definitive and public link between NetNut’s residential proxy network and the extensive Popa botnet. These comprehensive reports, including in-depth analyses from organizations like Synthient (founded by cybersecurity researcher Benjamin Brundage) and insights amplified by KrebsOnSecurity, provided irrefutable evidence of how NetNut populated Popa and distributed its malicious software via common household devices. KrebsOnSecurity played a pivotal role in disseminating these findings to a broader audience, shedding critical light on the clandestine operations of a publicly traded company.
- Early July 2026 (Law Enforcement Intervention): Leveraging the intelligence meticulously gathered by these private sector security entities and its own independent investigations, the FBI, supported by the Internal Revenue Service Criminal Investigation (IRS-CI), initiated the coordinated domain seizure operation. This decisive action effectively pulled the plug on NetNut’s primary operational infrastructure, disrupting its ability to route traffic and monetize its network.
- July 7, 2026 (Public Confirmation): NetNut’s primary homepage was visibly replaced with an official seizure notice from the FBI and IRS-CI, a clear and unambiguous declaration of law enforcement’s successful intervention. This prominent banner publicly announced the operation and extended gratitude to crucial industry partners such as Google, Lumen, and Shadowserver for their indispensable assistance in identifying, tracing, and ultimately dismantling hundreds of domains tied to the sprawling Popa botnet infrastructure.
- July 8, 2026 (Broader Corporate Impact): Shortly after the initial domain seizures, the website for NetNut’s parent company, Alarum Technologies (alarum[.]io), also began displaying an FBI seizure notice. This comprehensive corporate-level action signified the extensive nature of the law enforcement operation, indicating that investigators were scrutinizing the entire corporate entity and its involvement.
This chronological sequence underscores a growing and effective trend in modern cybersecurity, where law enforcement agencies increasingly rely on the advanced technical expertise and threat intelligence capabilities of private sector partners to combat sophisticated and globally distributed cyber threats. The seamless transition from investigative findings to active disruption demonstrates the formidable effectiveness of such multi-stakeholder collaborations.
Google’s Pivotal Role and Technical Insights
Among the industry partners, Google’s involvement proved particularly critical, as detailed in a comprehensive blog post published by the Google Threat Intelligence Group (GTIG) concurrently with the takedown announcement. The GTIG provided a stark and authoritative assessment of NetNut’s pervasive influence within the cybercriminal ecosystem. Their analysis revealed that NetNut’s proxy network was extensively resold and white-labeled by numerous third-party proxy providers, making its services a highly sought-after and trusted choice for a wide spectrum of threat actors seeking to obscure their digital footprints and maintain anonymity.

The GTIG’s extensive telemetry data showcased the sheer volume and diversity of malicious activity facilitated by NetNut. In a single week during June 2026, Google observed a staggering 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes. These groups ranged from opportunistic cybercriminals engaging in mass spam campaigns, credential stuffing, and web scraping, to highly sophisticated espionage groups conducting state-sponsored reconnaissance, data exfiltration, and targeted attacks. As Google’s GTIG explicitly stated, "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks." The ability to mask origin IP addresses is paramount for cybercriminals, as it allows them to launch attacks from what appears to be legitimate residential IP addresses, thereby evading traditional IP-based blacklists, reputation checks, and geographical restrictions.
Beyond merely facilitating attacks, NetNut’s operations posed a direct and significant threat to the privacy and security of the compromised devices’ owners. Google issued a stern warning: "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats." This highlights the insidious nature of such botnets, transforming a victim’s seemingly innocuous device into a gateway for further intrusion into their personal network, potentially exposing sensitive data, compromising other vulnerable IoT devices, or enabling lateral movement within the home network.
Google’s response extended beyond intelligence sharing. The tech giant took direct and aggressive action to hobble NetNut’s operations by disabling Google accounts and services that NetNut utilized for malware command and control (C2) infrastructure. Moreover, Google proactively shared critical technical intelligence regarding NetNut’s Software Development Kits (SDKs) and backend infrastructure with various platform providers, law enforcement agencies, and research firms globally. This intelligence enabled a broader defensive posture across the industry, allowing other entities to identify and block NetNut-related activities. Crucially, Google also moved swiftly to disable apps known to bundle NetNut’s various SDKs from its platforms, effectively cutting off a primary vector for device compromise and preventing new installations.
Corporate Response and Market Repercussions
In the immediate wake of the FBI’s operation, Alarum Technologies, NetNut’s publicly traded parent company, issued a statement through its legal counsel, Omer Weiss. Weiss acknowledged the FBI seizure and affirmed the company’s commitment to cooperate fully with investigators. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. This official response, while acknowledging the gravity of the situation, indicates an attempt to distance the parent company from the alleged misuse of its infrastructure by its clients and to cooperate with authorities, potentially to mitigate severe legal and financial repercussions.
The financial impact on Alarum Technologies has been immediate and severe. Following the FBI’s action and the public disclosure of NetNut’s definitive links to the Popa botnet, the company’s stock (NASDAQ: ALAR) suffered a dramatic and precipitous decline. Trading at $2.62 a share, it represented a staggering drop of approximately 67 percent over the past week. This significant devaluation underscores the critical importance of NetNut to Alarum’s overall business model and the severe blow the takedown has dealt to the company’s market standing, investor confidence, and future viability. The subsequent seizure of Alarum’s own corporate website further cemented the comprehensive nature of the law enforcement action, indicating that investigators are scrutinizing the entire corporate entity and its operational footprint.
Broader Impact on the Cybercrime Ecosystem
Cybersecurity experts widely believe that the takedown of NetNut will have a profound and lasting impact on the cybercrime community. Benjamin Brundage, founder of the proxy tracking service Synthient, whose firm was instrumental in linking Popa to NetNut, emphasized the significance of this disruption. Brundage noted that NetNut’s demise comes at a critical time when the cybercrime ecosystem was already struggling to recover from previous, high-profile law enforcement actions, particularly Google’s earlier takedown of IPIDEA. "I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage stated. He highlighted NetNut’s widespread adoption among resellers and its comparable standing with IPIDEA in terms of daily traffic volume, service quality, network size, and competitive pricing structure. The removal of two such dominant and highly utilized players within the residential proxy market within a relatively short span creates a substantial operational void for cybercriminals.
Furthermore, Brundage pointed to an additional, crucial benefit of the NetNut takedown: a potential reduction in the impact and frequency of large-scale distributed denial-of-service (DDoS) botnets. These destructive botnets have often leveraged poorly configured or exploited residential proxy services to amplify their attacks, making them harder to mitigate. In January, Synthient had revealed the existence of the "Kimwolf" botnet, which had quickly become one of the world’s largest DDoS botnets. Kimwolf operated by cunningly tunneling through IPIDEA proxy connections to gain unauthorized access to the local networks of TV box owners, subsequently infecting other Android-based devices behind the victim’s firewall. While many major proxy providers eventually took belated steps to block such egregious activity, resellers, often operating with less oversight and fewer security controls, were much slower to respond to the threat. The comprehensive disruption of NetNut, a key player in this illicit supply chain, is now expected to "have an impact on the DDoS botnets out there," Brundage affirmed, by significantly reducing the available pool of compromised devices that can be weaponized for such devastating attacks.
Google echoed this sentiment, asserting that today’s coordinated actions have caused "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." This substantial reduction in available proxy capacity directly hinders cybercriminals’ ability to launch large-scale operations requiring vast numbers of anonymized IP addresses, forcing them to seek less reliable or more expensive alternatives.

Challenges and the Future of Proxy Disruption
Despite the undeniable success of the NetNut takedown, both law enforcement and industry experts remain cautiously optimistic, recognizing the highly adaptive and resilient nature of the cybercrime ecosystem. Google’s GTIG report explicitly warns that proxy networks possess a remarkable ability to rebuild themselves, often by effectively white-labeling or reselling capacity from other, sometimes even rival, proxy services. This phenomenon was observed after the IPIDEA disruption, where individual networks demonstrated resilience by quickly acquiring capacity from competitors to maintain operations. "Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded, highlighting the intricate and often opaque interconnectedness of these illicit services.
The report further cautioned, "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers." This statement clearly outlines the ongoing and formidable challenge: the fight against residential proxy botnets is not a one-off battle but a continuous, evolving struggle that requires sustained, multi-faceted efforts targeting the entire interconnected infrastructure rather than isolated entities.
Consumer Vigilance: Protecting Home Networks
The persistent threat posed by residential proxy botnets underscores the critical need for heightened consumer awareness and proactive security measures. As KrebsOnSecurity has repeatedly warned, many low-cost, no-name TV streaming boxes widely sold on major e-commerce platforms often come either pre-installed with residential proxy software or require the installation of specific, often questionable, proxy SDKs to function for their advertised purpose, which frequently involves streaming pirated content. These devices, operating outside the legitimate and secure app ecosystems of reputable manufacturers, are prime targets for compromise.
Google’s advice to consumers is clear and unequivocal: prioritize reputable manufacturers for TV boxes and exercise extreme caution when installing any applications, regardless of their apparent utility. Devices built with the official Android TV OS and possessing Google Play Protect certification offer a significantly higher degree of security against malware and unauthorized activity. Consumers can verify this certification by following specific instructions provided by Google on its support pages. The core issue with the sketchy TV boxes routinely commandeered by botnets like Popa is their reliance on unofficial, modified Android operating systems that bypass the critical security safeguards and regular updates of Google’s Official Play Protect store.
The problem, however, extends beyond just obscure streaming devices. Even mainstream smart TVs from major manufacturers like Samsung and LG are vulnerable to this type of compromise. A recent report released last month by the proxy tracking company Spur revealed alarming statistics: 42 percent of apps available for download via the webOS operating system on LG smart TVs were found to include SDKs capable of turning the television into an always-on residential proxy node. Similarly, over a quarter of the apps developed for Samsung’s Tizen operating system contained comparable residential proxy components. This widespread integration of proxy SDKs, often for seemingly innocuous or "free" service purposes, highlights the ease with which ordinary household devices can be unknowingly weaponized, turning a living room entertainment system into a component of a global cybercrime network.
In conclusion, the FBI-led takedown of NetNut marks a significant victory in the ongoing battle against cybercrime, severely disrupting a key enabler of malicious activities and curtailing the vast Popa botnet. This operation sends a strong message to those who profit from exploiting unsuspecting users and abusing global internet infrastructure. However, the transient and highly adaptive nature of this "fluid ecosystem" demands continuous vigilance, sustained collaboration between law enforcement agencies and industry, and increased consumer education to effectively counter the evolving tactics of cybercriminals seeking to exploit residential networks for their illicit gains. The battle is far from over, but this operation represents a powerful statement against those who seek to profit from the unwitting compromise of millions of devices worldwide.
