FBI Seizes NetNut Proxy Domains Linked to Massive Popa Botnet and Israeli Firm Alarum Technologies

The Federal Bureau of Investigation (FBI), in a coordinated effort with international law enforcement and private sector cybersecurity partners, has successfully seized hundreds of internet domains associated with NetNut, a prominent residential proxy service. NetNut is operated by Alarum Technologies (NASDAQ: ALAR), a publicly-traded technology firm based in Israel. This sweeping enforcement action, which also involved the Internal Revenue Service Criminal Investigation (IRS-CI) division, marks a significant escalation in the global crackdown on "residential proxy" networks that leverage compromised consumer devices to facilitate cybercrime.
The seizure comes approximately two weeks after investigative findings from several cybersecurity research firms, publicized by KrebsOnSecurity, established a direct link between NetNut’s infrastructure and the "Popa" botnet. The Popa botnet is a massive network comprising at least two million devices—primarily smart TVs, streaming boxes, and Android-based hardware—that have been infected with malicious software. These devices were reportedly integrated into NetNut’s proxy network without the informed consent of their owners, effectively turning private home hardware into tools for large-scale digital abuse.
The Infrastructure of a Residential Proxy Giant
Residential proxy services like NetNut provide users with the ability to route their internet traffic through the IP addresses of real residential devices rather than data centers. While there are legitimate use cases for such services, such as localized market research or price monitoring, they are also highly prized by cybercriminals. By masking their true origin behind a residential IP, bad actors can bypass security filters that typically block traffic coming from known malicious servers or anonymous data centers.
Investigations into NetNut revealed that its "residential" nodes were not populated by willing participants in a bandwidth-sharing economy, but rather by victims of the Popa botnet. Security firms including Synthient, Spur, and Black Lotus Labs (the threat intelligence arm of Lumen Technologies) issued findings on June 19, 2026, detailing how NetNut distributed software development kits (SDKs) that found their way into various consumer applications. These SDKs converted home devices into "always-on" proxy nodes.
Once a device becomes an exit node for a proxy service, it serves as a relay for whatever traffic the service’s customers wish to send. In the case of NetNut, researchers found that this traffic was predominantly abusive. Common activities facilitated by the network included mass-scale web scraping, advertising fraud, and account takeover (ATO) attacks, where hackers use "credential stuffing" to break into personal accounts by trying millions of stolen password combinations.
Collaboration Between Law Enforcement and Big Tech
The dismantling of NetNut’s domain infrastructure was made possible through an extensive partnership between federal authorities and some of the world’s largest technology companies. The FBI’s seizure banner, which replaced the NetNut homepage, specifically credited Google, Lumen Technologies, and the Shadowserver Foundation for their technical assistance.
The Google Threat Intelligence Group (GTIG) published a comprehensive analysis following the seizure, shedding light on the scale of the threat. According to Google, NetNut’s services were not only sold directly to customers but were also "white-labeled" and resold by numerous third-party proxy providers. This created a sprawling ecosystem where a single botnet fueled multiple "brands" of proxy services, making it difficult for researchers to trace the original source of the malicious traffic.

Google’s telemetry data from a single week in June 2026 revealed the sheer volume of activity hosted by NetNut. The company observed 316 distinct clusters of threat actors—ranging from common cybercriminals to sophisticated state-sponsored espionage groups—utilizing NetNut exit nodes. These actors used the proxy network to mask their origin IP addresses while accessing victim environments, managing their own command-and-control infrastructure, and conducting password spray attacks against corporate and government targets.
The Security Risk to Home Networks
One of the most alarming aspects of the NetNut/Popa infrastructure is the direct security risk it poses to the owners of the compromised devices. When a consumer device, such as a smart TV, is transformed into a proxy exit node, it creates a bridge between the public internet and the owner’s private local network.
"When a consumer device becomes an exit node, unauthorized network traffic passes through it," Google’s GTIG explained in their report. "This means bad actors can access other private devices on the same home network, effectively exposing them to internet threats."
This "lateral movement" capability was demonstrated in earlier research regarding the "Kimwolf" botnet. In January 2026, the proxy tracking service Synthient revealed that cybercriminals had built Kimwolf—one of the world’s largest Distributed Denial-of-Service (DDoS) botnets—by tunneling through residential proxy connections into the local networks of TV box owners. Once inside the local network, the attackers could infect other Android-based devices sitting behind the victim’s firewall, such as smartphones or tablets, which were previously thought to be secure.
Financial Fallout and Corporate Response
The legal action has had an immediate and devastating impact on Alarum Technologies, the parent company of NetNut. Since the FBI seizure was initiated, the company’s stock, traded on the NASDAQ under the symbol ALAR, has plummeted. As of the latest market reports, the stock was trading at approximately $2.62 per share, representing a staggering 67 percent decline in value over the course of a single week.
The company’s official website, alarum.io, has also been seized by the FBI, further signaling the totality of the enforcement action. In response to the crisis, Alarum’s legal counsel, Omer Weiss, issued a statement indicating that the company is attempting to cooperate with federal investigators.
"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. However, the depth of the FBI’s involvement, which includes the IRS Criminal Investigation division, suggests that authorities are looking beyond mere "misuse" by customers and are potentially investigating the company’s role in the acquisition and management of its botnet-driven IP pool.
The Persistence of the Proxy Ecosystem
While the seizure of hundreds of NetNut domains is a major victory for cybersecurity, experts warn that the battle is far from over. The residential proxy market has proven to be remarkably resilient. When a major player is taken down, its competitors often absorb the displaced traffic, or the original operator attempts to rebuild using different infrastructure.

Benjamin Brundage, the founder of Synthient, noted that NetNut had surged in popularity specifically because of a previous law enforcement action. Earlier in 2026, Google and other partners successfully disrupted IPIDEA, which was then NetNut’s largest competitor. Following the IPIDEA takedown, NetNut became the go-to provider for resellers and cybercriminals, matching IPIDEA in terms of daily traffic, size, and affordability.
Google’s threat researchers expressed high confidence that many popular residential proxy brands are currently whitelabeling what remains of the NetNut infrastructure. "Observations after the disruption of IPIDEA proved that individual networks can appear resilient," the GTIG report concluded. "When faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller."
Consumer Protection: The Danger of "Sketchy" TV Boxes
The NetNut case highlights a growing trend in the cybercrime world: the exploitation of low-cost, unbranded Android TV streaming boxes. These devices, which are often sold on major e-commerce platforms for $20 to $50, frequently come pre-installed with malware or proxy SDKs.
In many instances, these devices are marketed as "fully loaded" tools for streaming pirated movies and live sports. To function, they often require the user to install unofficial Android operating systems or third-party apps that do not pass through the security checks of the official Google Play Store. These "off-market" ecosystems are the primary breeding ground for the Popa botnet.
Cybersecurity experts and Google have issued clear advice for consumers: stick to name-brand streaming devices from reputable manufacturers. Furthermore, users are encouraged to verify that their devices are "Play Protect" certified. Devices running official Android TV OS provide a layer of security that prevents the background installation of proxy SDKs.
The threat is not limited to cheap streaming boxes. A recent report from the tracking company Spur found that a significant percentage of apps available on the official app stores for Samsung (Tizen) and LG (webOS) smart TVs also include residential proxy SDKs. According to Spur, 42 percent of apps available on LG’s webOS and over 25 percent of apps on Samsung’s Tizen include components that turn the television into a proxy node.
Conclusion and Future Outlook
The seizure of NetNut’s domains marks a pivotal moment in the fight against botnet-backed proxy services. By targeting a publicly traded company and dismantling its core infrastructure, the FBI and its partners have sent a clear message to the industry: the era of "don’t ask, don’t tell" regarding the source of residential IP addresses is ending.
However, the "fluid ecosystem" of proxy providers means that law enforcement must remain vigilant. As the NetNut infrastructure degrades, the millions of devices currently in the Popa botnet remain vulnerable to being hijacked by the next emerging proxy provider. Creating lasting disruption will require a sustained, multi-layered approach that combines domain seizures, app store cleaning, and increased consumer awareness regarding the digital hygiene of their smart home devices. For now, the downfall of NetNut serves as a stark reminder that the "residential" IPs sold to mask cybercrime are often stolen from the very consumers the hackers intend to target.






