FBI and Global Industry Partners Seize Infrastructure of NetNut Residential Proxy Network Linked to Global Popa Botnet

The Federal Bureau of Investigation, in coordination with the Internal Revenue Service Criminal Investigation division and a coalition of private-sector technology leaders, has executed a large-scale operation to dismantle the digital infrastructure of NetNut, a prominent residential proxy service. NetNut, operated by the NASDAQ-listed Israeli firm Alarum Technologies, has been identified by law enforcement and cybersecurity researchers as the primary backbone for the Popa botnet, a massive network of over two million compromised devices worldwide. The seizure involved hundreds of domains used to facilitate the proxy service, effectively severing the connection between cybercriminals and the vast pool of hijacked consumer hardware they utilized to mask illicit activities.
This law enforcement action follows a series of investigative reports published in June 2026 by multiple cybersecurity firms, which provided evidence that NetNut’s business model relied heavily on the non-consensual enlistment of consumer electronics. These devices, ranging from smart televisions to Android-based streaming boxes, were infected with specialized software that transformed them into "exit nodes." These nodes were then rented out to third parties, allowing them to route internet traffic through home networks to bypass security filters and geographic restrictions.
The Mechanics of the Popa Botnet and NetNut Infrastructure
The Popa botnet represents a sophisticated evolution in the "Proxy-as-a-Service" market. Unlike traditional botnets that focus primarily on direct attacks, Popa’s primary value lies in its residential nature. Residential proxies are highly coveted by both legitimate data scrapers and malicious actors because the traffic they generate appears to originate from genuine home internet connections. This makes it significantly harder for automated security systems to distinguish between a legitimate consumer and a cybercriminal.
According to findings from the Google Threat Intelligence Group, NetNut’s infrastructure was not only used directly by its customers but was also widely "white-labeled" or resold by other proxy providers. This created a complex web of interconnected services that allowed various threat actors to obfuscate their origins. During a single week in June 2026, Google researchers identified 316 distinct clusters of threat actors—ranging from petty cybercriminals to state-sponsored espionage groups—utilizing NetNut’s exit nodes.
The infection vector for the Popa botnet typically involves the distribution of Software Development Kits (SDKs) embedded within seemingly innocuous applications. These SDKs are often found in third-party apps for streaming pirated content or "free" utilities offered on unofficial app stores. Once a user installs such an app on a smart TV or a mobile device, the NetNut SDK activates, turning the device into a permanent proxy node. This occurs often without the user’s explicit consent or understanding of the technical implications, which include increased data usage, potential device slowdowns, and significant security vulnerabilities for the entire local home network.
Chronology of the Takedown and Investigative Milestones
The dismantling of NetNut’s infrastructure is the culmination of several months of escalating pressure from the cybersecurity community and law enforcement agencies.
In January 2026, the proxy tracking service Synthient revealed the existence of the "Kimwolf" botnet. Researchers discovered that cybercriminals were using IPIDEA—at the time, NetNut’s largest competitor—to tunnel into the local networks of home users. By exploiting poorly configured proxy connections on Android-based TV boxes, attackers could bypass firewalls to infect other devices on the same Wi-Fi network, such as laptops and smart home hubs. This discovery highlighted the extreme danger posed by residential proxy networks that lack rigorous oversight.

By June 19, 2026, the focus shifted toward NetNut. Three independent security firms published concurrent reports linking NetNut to the Popa botnet. These reports detailed how NetNut’s growth coincided with the degradation of other proxy networks, suggesting that Alarum Technologies was aggressively capturing market share by absorbing botnet-infected traffic.
The definitive strike occurred in early July 2026. Visitors to the NetNut homepage were met not with the company’s usual marketing materials, but with a seizure banner featuring the insignias of the FBI and the IRS. The notice credited a wide array of industry partners, including Google, Lumen Technologies’ Black Lotus Labs, and The Shadowserver Foundation, for their technical assistance in mapping and disabling the botnet’s command-and-control architecture.
Corporate and Financial Consequences for Alarum Technologies
The involvement of a publicly-traded company in such a significant botnet operation has sent shockwaves through the financial markets. Alarum Technologies, which trades on the NASDAQ under the ticker ALAR, saw its valuation plummet following the FBI’s intervention. Within a week of the domain seizures, the company’s stock price fell by approximately 67 percent, dropping to $2.62 per share as investors reacted to the legal and reputational risks associated with the federal investigation.
Omer Weiss, legal counsel for Alarum Technologies, issued a statement following the seizure, asserting that the company is cooperating with federal authorities. Weiss maintained that the company takes the allegations seriously and intends to investigate any "misuse" of its infrastructure. However, the scale of the FBI’s action suggests that investigators believe the integration between NetNut and the Popa botnet was foundational rather than incidental.
The seizure of the alarum.io domain, in addition to the netnut.io domains, indicates that the investigation is targeting the corporate entity itself rather than just its subsidiary service. This move by the FBI and IRS signals a potential shift in how law enforcement handles "dual-use" technology companies that provide services used predominantly for illicit purposes.
Technical Analysis of Threat Actor Activity
Google’s GTIG provided a detailed analysis of how threat actors leveraged NetNut. The proxy network was a favorite tool for executing "password spray" attacks. In these attacks, a hacker attempts to log into thousands of different accounts using a few common passwords. By rotating through NetNut’s millions of residential IP addresses, the attacker can avoid triggering account lockouts or IP-based rate limiting, as each attempt appears to come from a different home in a different part of the world.
Furthermore, the presence of a proxy node on a consumer device creates a "backdoor" into the home. When a smart TV becomes an exit node, unauthorized traffic passes through the device’s network interface. This exposure allows sophisticated actors to conduct reconnaissance on the local area network (LAN), identifying other vulnerable devices like unpatched routers or network-attached storage (NAS) units.
Google’s response to these findings was multi-faceted. The company disabled Google accounts and services that were being used as part of NetNut’s command-and-control system. Additionally, Google Play Protect was updated to identify and disable applications known to bundle the malicious NetNut SDKs, providing a layer of automated protection for Android users.

Broader Impact on the Residential Proxy Ecosystem
The takedown of NetNut is expected to cause significant, albeit potentially temporary, disruption in the cybercrime "supply chain." Benjamin Brundage, founder of Synthient, noted that NetNut had become the go-to provider for resellers following the disruption of IPIDEA earlier in the year. "NetNut was on par with the largest players in terms of daily traffic, quality, and price," Brundage stated. Its removal from the market leaves a massive void that cybercriminals will struggle to fill in the short term.
However, experts warn that the residential proxy market is highly resilient. When one network is dismantled, operators often migrate their traffic to competitors or "white-label" capacity from other existing botnets. Google’s report emphasized that creating a lasting impact requires a sustained, industry-wide effort to target the underlying SDKs and the hardware manufacturers that allow these vulnerabilities to persist.
The prevalence of "no-name" Android TV boxes remains a primary concern. These devices are frequently sold on major e-commerce platforms with pre-installed firmware that is not certified by Google. These unofficial versions of the Android operating system often lack essential security updates and come pre-loaded with proxy software to facilitate the streaming of pirated content—a trade-off that many consumers unknowingly make at the expense of their digital security.
Recommendations for Consumers and Industry Stakeholders
In light of the NetNut seizure, cybersecurity experts are urging consumers to audit their home networks. The primary targets of the Popa botnet—smart TVs and streaming boxes—are often the least-monitored devices in a household. Consumers are advised to:
- Verify Certification: Ensure that any Android-based TV device is "Play Protect Certified." This can be checked within the Google Play Store settings.
- Avoid Unofficial Hardware: Stick to reputable brands for streaming devices, as these manufacturers are more likely to provide regular security patches and vet their software ecosystems.
- Audit Installed Apps: Remove any applications that were not downloaded from an official app store (such as the Google Play Store, Amazon Appstore, or the LG/Samsung native stores).
- Monitor Network Traffic: Users with technical proficiency should check their router logs for unusual outbound traffic, particularly during times when the TV or streaming box is not in active use.
For the broader technology industry, the NetNut case serves as a landmark example of the necessity for public-private partnerships in dismantling cybercrime infrastructure. The cooperation between the FBI, IRS, and companies like Google and Lumen demonstrates that while the internet is vast, the infrastructure required to run a global botnet is finite and vulnerable to coordinated legal and technical pressure.
As the investigation into Alarum Technologies and the Popa botnet continues, the focus will likely shift toward the developers of the SDKs and the resellers who facilitated the monetization of compromised consumer devices. The collapse of NetNut marks a significant victory for internet safety, but it also underscores the ongoing battle against the commercialization of cybercrime.







