In a significant blow to the illicit online economy, the Federal Bureau of Investigation (FBI), in collaboration with a consortium of industry partners, has successfully dismantled a vast network of hundreds of domains associated with NetNut, a prominent residential proxy service operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). This decisive action follows closely on the heels of investigative reports from multiple security firms, including KrebsOnSecurity, which linked NetNut to the Popa botnet. The Popa botnet, a formidable collection of at least two million compromised devices, has been surreptitiously leveraged with minimal to no consent from its unwitting victims.
The exposé on NetNut’s involvement with the Popa botnet emerged on June 19th, when three independent security firms simultaneously published their findings. These reports detailed how NetNut functions as a residential proxy network, effectively populating the Popa botnet by distributing software to common household devices such as smart TVs and streaming boxes. Once installed, this software transforms these devices into perpetually active residential proxy nodes. These nodes are then rented out to a clientele predominantly engaged in malicious and intrusive online activities, including large-scale content scraping, sophisticated advertising fraud schemes, and audacious account takeover operations.
The immediate aftermath of the FBI’s intervention was starkly visible on NetNut’s homepage, which was replaced by an official seizure notice from the FBI and the Internal Revenue Service Criminal Investigation division. This notice explicitly acknowledged the crucial assistance provided by industry collaborators, including Google, Lumen, and Shadowserver, in dismantling the hundreds of domains tied to the Popa botnet. For a considerable period, the Popa botnet has been virtually synonymous with NetNut’s residential proxy infrastructure, making this seizure a direct assault on their operational capabilities.
The Google Threat Intelligence Group (GTIG) elaborated on the intricate workings of NetNut’s network in a blog post published concurrently with the FBI’s announcement. GTIG highlighted that NetNut’s proxy network is not only widely resold but also white-labeled by numerous third-party proxy providers. This widespread availability makes its services highly attractive to cybercriminals seeking to obscure the origins of their illicit traffic. In a single week during June 2026, GTIG observed a staggering 316 distinct clusters of threat actors, encompassing both cybercriminal syndicates and espionage groups, utilizing suspected NetNut exit nodes.
"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google’s GTIG stated. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."

Google’s proactive role in this operation was substantial. The tech giant disabled Google accounts and services that NetNut was utilizing for malware command and control. Moreover, Google shared critical technical intelligence regarding NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement agencies, and research firms. The company also took action to disable applications known to bundle NetNut’s various SDKs, further crippling their reach.
Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, confirmed that the company was aware of the FBI’s seizure and was cooperating with the ongoing investigation. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated in a written statement.
Benjamin Brundage, founder of the proxy tracking service Synthient and one of the firms that published evidence linking the Popa botnet to NetNut and Alarum Technologies, expressed optimism about the impact of the seizures. Brundage noted that the domain seizures appear to have effectively disrupted both the Popa botnet and the NetNut proxy network that underpins it. He further suggested that NetNut’s apparent demise will represent a significant setback for the cybercrime community, which was already reeling from earlier legal actions taken by Google that disrupted the infrastructure of NetNut’s primary competitor, IPIDEA.
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage remarked. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."
The ramifications of this coordinated takedown extend beyond the immediate disruption of NetNut and Popa. Brundage posited that it could also lessen the impact of large distributed denial-of-service (DDoS) botnets that have been built upon the foundation of poorly secured residential proxy services. He recalled Synthient’s January revelation about the Kimwolf botnet, which exploited IPIDEA proxy connections to tunnel into the local networks of TV box owners, subsequently infecting other Android-based devices behind the victim’s firewall. While many of the larger proxy providers have taken steps to curb such activities, resellers of these networks have been slower to address the threat. "In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," Brundage asserted.
Google, for its part, estimates that the recent actions have caused "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." However, the company cautioned that proxy networks possess a degree of resilience and can reconstitute themselves by effectively reselling services from other providers, a pattern observed with IPIDEA in recent months.

"Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."
As KrebsOnSecurity has consistently warned, many of the unbranded TV streaming boxes available on major e-commerce platforms are either pre-installed with residential proxy software or necessitate the installation of proxy SDKs for full functionality, often for the streaming of pirated content. Google’s advice remains pertinent: consumers should opt for reputable brands from established manufacturers for TV boxes and exercise caution when installing third-party applications. Devices that are not built with the official Android TV OS and Play Protect certification are particularly vulnerable.
The compromised TV boxes commandeered by the Popa botnet and other threats often run unofficial Android operating systems that bypass Google’s Play Protect safeguards. Consumers can verify the authenticity of their device’s operating system by consulting Google’s official instructions.
The threat extends beyond TV boxes. Even users of smart TVs from brands like Samsung and LG can find their devices enrolled in residential proxy networks through the installation of seemingly innocuous applications. A report from Spur.us last month revealed that a substantial percentage of apps available on LG’s webOS and Samsung’s Tizen operating systems include SDKs that transform televisions into always-on residential proxy nodes.
An update on July 8th, 2:34 p.m. ET, confirmed that Alarum Technologies’ website, alarum[.]io, now also displays an FBI seizure notice. The company’s stock has experienced a dramatic decline since the FBI’s action, plummeting by approximately 67 percent over the past week and trading at $2.62 per share. This multifaceted operation underscores the evolving landscape of cybercrime and the critical importance of collaborative efforts between law enforcement and the private sector to combat it.

