In a significant blow against cybercriminal infrastructure, the Federal Bureau of Investigation (FBI), in collaboration with a coalition of industry partners, has successfully dismantled hundreds of domains associated with NetNut, a vast residential proxy service operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). This coordinated takedown, announced today, follows closely on the heels of investigative findings published by KrebsOnSecurity and multiple security firms that linked NetNut to the Popa botnet, a sprawling network estimated to comprise at least two million compromised devices operating with minimal or no consent from their owners.

The disruption came to light on June 19th, when three independent security firms concurrently released reports detailing how NetNut functions as a residential proxy network that fuels the Popa botnet. These reports highlighted that NetNut distributes software designed for common household devices, including smart TVs and streaming boxes. Once installed, this software transforms these devices into perpetually active residential proxy nodes. These nodes are then rented out to various entities, predominantly those engaged in illicit online activities such as mass content scraping, advertising fraud, and account takeover schemes.

The impact of the FBI’s action was immediately visible on NetNut’s homepage, which was replaced by a seizure banner from the FBI and the Internal Revenue Service Criminal Investigation division. The notice publicly acknowledged the crucial assistance provided by industry partners, including Google, Lumen, and Shadowserver, in dismantling the extensive network of domains linked to the Popa botnet, which security experts have long identified as being intrinsically tied to NetNut’s residential proxy infrastructure.

Google’s Threat Intelligence Group (GTIG) provided further context in a blog post released today, explaining that NetNut’s proxy network is extensively resold and white-labeled by numerous third-party proxy providers. The GTIG noted that cybercriminals and espionage groups heavily rely on NetNut’s services to mask the origin of their malicious traffic. In a single week during June 2026, GTIG observed 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes. "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," the GTIG wrote. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."

FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security

Google’s involvement was multifaceted; the company disabled Google accounts and services that NetNut utilized for command and control of its malware. Additionally, Google shared critical technical intelligence regarding NetNut’s software development kits (SDKs) and backend infrastructure with platform providers, law enforcement, and research firms. The company also took action to disable applications known to bundle various NetNut SDKs.

Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, confirmed the company’s awareness of the FBI’s seizure and stated their full cooperation with the ongoing investigation. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated in a written release.

Benjamin Brundage, founder of the proxy tracking service Synthient and one of the firms that published evidence linking the Popa botnet to NetNut and Alarum Technologies last month, indicated that the domain seizures have significantly disrupted both the Popa botnet and the underlying NetNut proxy network. Brundage suggested that NetNut’s apparent downfall will present a substantial challenge for the cybercrime community, which was already dealing with the aftermath of legal actions taken by Google earlier this year that targeted IPIDEA, NetNut’s largest competitor.

"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage commented. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."

Beyond the direct impact on proxy services, Brundage posited that the takedown of NetNut and the Popa botnet could also mitigate the effectiveness of large distributed denial-of-service (DDoS) botnets. These botnets have historically leveraged poorly configured residential proxy services. Synthient had previously revealed how cybercriminals had constructed the world’s largest DDoS botnet, Kimwolf, by tunneling through IPIDEA proxy connections into the local networks of TV box owners, subsequently infecting other Android-based devices behind the victim’s firewall. While major proxy providers have taken steps to counter such activities, resellers have been slower to adapt. "In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," Brundage noted.

FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security

Google estimates that today’s actions have resulted in "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." However, the company cautioned that proxy networks can reconstitute themselves by reselling capacity from other services, a strategy observed with IPIDEA in recent months. "Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."

As KrebsOnSecurity has frequently warned, many low-cost TV streaming boxes sold on major e-commerce platforms either come pre-installed with residential proxy software or require the installation of proxy SDKs for full functionality, often for streaming pirated content. Google advises consumers to opt for name-brand TV boxes from reputable manufacturers and to exercise caution with app installations. Devices compromised by the Popa botnet and similar threats often run unofficial Android operating systems that lack Google’s Play Protect certification. Consumers can verify official Android TV OS and Play Protect certification by following Google’s provided instructions.

The threat extends beyond TV boxes; smart TVs from manufacturers like Samsung and LG can also become part of residential proxy networks through app installations. A recent report from Spur.us found that 42% of apps available for LG smart TVs via the webOS operating system contain SDKs that turn the television into an always-on residential proxy node. Similarly, over a quarter of apps designed for Samsung’s Tizen operating system exhibited similar residential proxy components.

An update at 4:24 p.m. ET incorporated a statement from an attorney representing Alarum Technologies. A further update on July 8th at 2:34 p.m. ET revealed that Alarum Technologies’ website, alarum[.]io, also now displays an FBI seizure notice. The company’s stock has experienced a significant decline following the FBI’s action, trading at $2.62 per share, representing a roughly 67% drop over the past week.