Digital Siege: FBI Dismantles NetNut Proxy Network Amidst Massive Botnet Exposure

In a sweeping coordinated strike against the infrastructure of modern cybercrime, the Federal Bureau of Investigation (FBI), in collaboration with the Internal Revenue Service (IRS) Criminal Investigation division and a coalition of private sector cybersecurity leaders, has successfully seized hundreds of domains associated with NetNut. The service, a prominent residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies [NASDAQ: ALAR], had long been identified by security researchers as a primary engine for malicious traffic, including botnet operations, advertising fraud, and large-scale account takeover campaigns.
The takedown, which saw NetNut’s homepage replaced by a federal seizure banner, marks a significant escalation in the war against the "residential proxy" ecosystem—a shadowy industry that commoditizes the internet connections of unsuspecting consumers to provide a cloak of anonymity for global threat actors.
The Chronology: From Research Discovery to Federal Action
The collapse of NetNut was not a sudden event, but rather the culmination of an intense period of scrutiny that intensified in late June 2026.
- June 19, 2026: Three independent cybersecurity research firms simultaneously published findings linking NetNut to the "Popa" botnet. This vast network, comprising at least two million compromised devices—predominantly smart TVs, streaming boxes, and home IoT devices—was being utilized as a residential proxy engine.
- Late June 2026: Google’s Threat Intelligence Group (GTIG) began a deep-dive analysis, identifying NetNut as a central hub for cybercriminal activity. They observed hundreds of distinct threat actor clusters utilizing NetNut exit nodes to conduct espionage and credential stuffing.
- Early July 2026: The FBI and IRS-CI finalized their investigation, obtaining legal authorization to seize the primary domains and infrastructure supporting the NetNut network.
- July 8, 2026: The operation went live. By mid-day, the NetNut homepage and its parent company portal,
alarum.io, were both served with federal seizure notices. Following the news, Alarum Technologies’ stock price plummeted, losing approximately 67% of its value in a single week to settle at $2.62 per share.
The Anatomy of the Popa Botnet
The Popa botnet operates on a model of "forced participation." NetNut’s software development kits (SDKs) are frequently bundled with low-cost, uncertified Android streaming devices and certain applications for smart TVs. Once installed, these devices are transformed into "always-on" residential proxy nodes.
For the end-user, the device appears to be functioning normally. In the background, however, the hardware is routing external, often malicious, traffic through the user’s home IP address. This effectively hides the true origin of the traffic, allowing cybercriminals to bypass IP-based security filters and geofencing.
Benjamin Brundage, founder of the proxy tracking firm Synthient, notes that the integration is seamless. "NetNut’s infrastructure was synonymous with the Popa botnet," Brundage explained. "By leveraging residential IPs, these actors can perform mass content scraping, advertising fraud, and targeted account takeovers while appearing to be legitimate home users."
Google’s research further highlights the danger to the consumer. Because the compromised device acts as an open gate on the home network, bad actors can occasionally pivot from the streaming box to other private devices on the same local network—such as home computers, NAS drives, and security cameras—thereby exposing the entire household to further exploitation.
Supporting Data: A Global Ecosystem of Abuse
The impact of NetNut is quantified by the sheer volume of illicit traffic passing through its nodes. According to Google’s Threat Intelligence Group, in a single week in June, they monitored 316 distinct clusters of threat actors—ranging from petty cybercriminals to state-sponsored espionage groups—relying exclusively on NetNut exit nodes to mask their activities.

The ecosystem is notoriously fluid. When one provider is dismantled, others often absorb the capacity. The industry is characterized by "white-labeling," where third-party proxy providers purchase access to the NetNut backend to sell as their own "premium" residential proxy services. This creates a recursive problem where the true origin of the proxy network becomes intentionally obscured, making it difficult for ISPs and security vendors to block malicious traffic at the source.
Spur, another proxy tracking organization, recently conducted an audit of smart TV operating systems. Their findings were startling:
- 42% of apps on the LG webOS platform contained SDKs capable of turning the television into an active residential proxy node.
- Over 25% of apps on Samsung’s Tizen OS were found to contain similar proxy components.
These findings confirm that the residential proxy market is no longer limited to PCs and mobile devices; it has successfully permeated the living room, leveraging the low security standards of consumer IoT hardware.
Official Responses and Corporate Accountability
The involvement of Alarum Technologies, a publicly traded entity, adds a layer of corporate accountability to this investigation. Following the seizure, Omer Weiss, legal counsel for Alarum, issued a statement indicating the company’s intent to cooperate.
"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.
However, the disconnect between the company’s stated business model and the reality of the Popa botnet remains a point of contention. While Alarum may characterize its services as legitimate "data collection" tools, the FBI’s intervention suggests that the "misuse" was not an outlier, but a fundamental feature of the network’s architecture.
Google, which played a pivotal role in the takedown, noted that it has taken aggressive measures to purge the threat. "Google has disabled accounts and services used by NetNut for malware command and control," the company stated in a recent blog post. "We have also shared technical intelligence regarding the SDKs and backend infrastructure with law enforcement, platform providers, and the wider security community."
Implications: The Long Road to Remediation
The seizure of NetNut is a significant victory, but experts warn that it is not a final solution. The "whack-a-mole" nature of the proxy market means that operators are quick to pivot.

1. The Rise of Resellers
Following the disruption of IPIDEA earlier this year, observers noted that many operators simply shifted their traffic to other providers or began "white-labeling" their services through smaller, less-scrutinized networks. Google warns that the residential proxy ecosystem is highly resilient and that "individual networks can appear resilient" even after significant degradation.
2. The Threat to IoT and Streaming Devices
The most enduring lesson from the NetNut/Popa case is the risk associated with non-certified, low-cost Android TV boxes. Many of these devices are pre-loaded with malicious firmware or require the installation of unofficial apps to function, effectively inviting a botnet into the user’s home.
Security experts strongly advise consumers to:
- Stick to reputable brands: Avoid "no-name" streaming devices that do not carry official Android TV or Google Play Protect certification.
- Audit Installed Apps: Be judicious about what software is installed on smart TVs. If an app provides "free" access to premium content, it is highly likely to be monetizing your network bandwidth in the background.
- Verify Certification: Consumers can verify if their device is officially certified by checking the Android TV OS support pages.
3. A Shift in Enforcement Strategy
The collaboration between the FBI, IRS-CI, Google, Lumen, and Shadowserver signals a new, more aggressive phase in law enforcement. By targeting not just the botnet, but the commercial entities that provide the infrastructure for these botnets, authorities are attempting to increase the cost of doing business for proxy operators.
As Benjamin Brundage notes, the destruction of the NetNut/Popa infrastructure will have a ripple effect on the broader cybercrime landscape. "In terms of all these TV box devices getting compromised, it will have a tangible impact on the DDoS botnets currently active," he explained.
The takedown of NetNut serves as a sobering reminder of how easily the modern home has become a pawn in the global cyber-warfare landscape. While the seizure of these hundreds of domains is a win for internet security, the underlying demand for residential proxies remains high. Until consumers become more discerning about the hardware and software they bring into their homes, the residential proxy industry will likely continue to evolve, finding new ways to exploit the very devices meant to entertain us.
