The Federal Bureau of Investigation (FBI), in a significant coordinated effort with industry partners, has successfully dismantled hundreds of domains associated with NetNut, a vast residential proxy service operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). This decisive action follows closely on the heels of investigative reports published by KrebsOnSecurity just two weeks prior, which meticulously detailed the connections between NetNut and the Popa botnet. The Popa botnet, a sprawling network comprising at least two million compromised devices, operates with minimal to no consent from its unwitting victims, raising serious concerns about privacy and security.
The critical findings, independently published on June 19th by three distinct security firms, unequivocally established that NetNut functions as a residential proxy network that actively populates the Popa botnet. This network distributes malicious software designed for devices commonly found in households, including smart TVs and streaming boxes. The proprietary software from NetNut effectively transforms these consumer devices into perpetually active residential proxy nodes. These nodes are then leased to third parties who predominantly leverage them for relaying a high volume of abusive and intrusive internet traffic. This illicit activity encompasses a range of malicious endeavors, such as mass content scraping, sophisticated advertising fraud schemes, and unauthorized account takeover activities, underscoring the far-reaching implications of NetNut’s operations.
On the morning of the seizure, the NetNut homepage was conspicuously replaced with an official seizure notice from the FBI, complemented by a declaration from the Internal Revenue Service Criminal Investigation division. This notice extended gratitude to a consortium of industry partners, including Google, Lumen, and Shadowserver, for their instrumental contributions in dismantling hundreds of domains intrinsically linked to the Popa botnet. Security experts have long recognized the Popa botnet as being virtually synonymous with NetNut’s residential proxy infrastructure, highlighting the symbiotic and illicit relationship between the two.
In a detailed blog post released today, the Google Threat Intelligence Group (GTIG) elaborated on NetNut’s pervasive influence within the cybercriminal ecosystem. The GTIG revealed that NetNut’s proxy network is extensively resold and white-labeled by a multitude of third-party proxy providers, making its services highly sought after by cybercriminals aiming to obscure the origins of their malicious traffic. The GTIG’s research identified a staggering 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes within a single week in June 2026. This diverse group included sophisticated cybercriminal organizations and state-sponsored espionage groups, demonstrating the breadth of NetNut’s utility for nefarious purposes.
"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google’s GTIG stated in their official blog post. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats." This statement from Google directly illustrates the profound security risks posed to ordinary consumers whose devices are unwittingly exploited.
Google’s proactive measures were multifaceted. The company disabled Google accounts and services that were being utilized by NetNut for command and control of malware. Furthermore, Google shared critical technical intelligence concerning NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement agencies, and research firms. Crucially, Google also took action to disable applications known to bundle NetNut’s various SDKs, thereby preventing further proliferation of the malicious software.

Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, acknowledged the FBI’s seizure and confirmed the company’s cooperation with investigators. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated in a written statement. This statement indicates a recognition of the gravity of the situation and a commitment to assisting in the ongoing investigation.
Benjamin Brundage, founder of the proxy tracking service Synthient, one of the firms that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies, provided further insights into the impact of the seizure. Brundage observed that the domain seizures appear to have effectively disrupted both the Popa botnet and the NetNut proxy network that underpins it. He posited that NetNut’s apparent demise will represent a significant setback for the cybercrime community, which was already reeling from earlier legal actions taken by Google that resulted in the seizure of infrastructure for NetNut’s primary competitor, IPIDEA.
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage remarked. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it." His analysis highlights NetNut’s prominent position in the market and the ripple effect its removal will have.
The coordinated takedown of the NetNut and Popa botnet infrastructure may yield an additional, significant benefit: a reduction in the effectiveness of large distributed denial-of-service (DDoS) botnets that have historically been built upon the foundation of poorly secured residential proxy services. Brundage recalled that in January, Synthient revealed how cybercriminals had constructed the world’s largest DDoS botnet, Kimwolf, by exploiting IPIDEA proxy connections to infiltrate the local networks of TV box owners and subsequently infect other Android-based devices residing behind the victim’s firewall. While many of the larger proxy providers had begun to implement measures to thwart such activities, resellers of these major proxy networks had been considerably slower to address the escalating threat.
"In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," Brundage stated, emphasizing the potential positive ramifications for online security.
Google, for its part, estimates that today’s actions have resulted in "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." However, the company issued a cautionary note, warning that proxy networks possess the inherent ability to reconstitute themselves by effectively reselling services from other proxy providers, a tactic observed with IPIDEA in recent months.
"Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers." This statement underscores the dynamic and adaptive nature of the cybercrime landscape and the need for ongoing, comprehensive enforcement efforts.

As KrebsOnSecurity has consistently warned, a significant number of inexpensive TV streaming boxes available on major e-commerce platforms either come pre-installed with residential proxy software or necessitate the installation of proxy SDKs to function for their intended purpose, which often involves streaming pirated content. Google’s advice in this regard is clear and pertinent: consumers should prioritize purchasing TV boxes from reputable manufacturers and exercise caution and judiciousness when selecting and installing applications.
The compromised TV boxes that fall victim to the Popa botnet and other threats typically utilize unofficial Android operating systems that operate outside the security framework of Google’s Official Play Protect store. Google advises consumers to verify if a device is built with the official Android TV OS and Play Protect certification by following specific instructions provided on their support website.
The threat is not confined to TV streaming boxes; even individuals without such devices can find their smart TVs inadvertently enrolled in residential proxy networks. This can occur through the installation of one of the thousands of applications available for download on Samsung and LG smart TVs. A report released last month by the proxy tracking company Spur found that a substantial 42 percent of apps available for download via the webOS operating system on LG smart TVs contained SDKs that transform the television into an always-on residential proxy node. Furthermore, Spur’s research indicated that over a quarter of the apps developed for Samsung’s Tizen operating system exhibited similar residential proxy components.
Update, 4:24 p.m. ET: A statement was included post-publication from an attorney representing NetNut parent Alarum Technologies, acknowledging the situation and pledging cooperation.
Update, July 8, 2:34 p.m. ET: The official website for Alarum Technologies, alarum[.]io, now also displays a seizure notice from the FBI. The company’s stock has experienced a severe decline following the FBI’s action, currently trading at $2.62 per share, representing an approximate 67 percent decrease over the past week, reflecting the significant financial impact of the seizure.

