FBI Seizes NetNut Proxy Infrastructure Following Links to Global Popa Botnet and Malicious Cyber Activity

The Federal Bureau of Investigation (FBI), in a coordinated effort with international law enforcement and private sector security partners, has executed a massive seizure of hundreds of domains associated with NetNut, a prominent residential proxy service operated by the Israeli-based firm Alarum Technologies [NASDAQ: ALAR]. This significant enforcement action marks a pivotal moment in the ongoing battle against large-scale botnets that exploit consumer electronics to facilitate global cybercrime. The seizure comes less than two weeks after independent security researchers and multiple cybersecurity firms published comprehensive reports linking NetNut’s infrastructure to the "Popa" botnet, a vast network of at least two million compromised devices used to mask malicious internet traffic.
The operation, which also involved the Internal Revenue Service Criminal Investigation (IRS-CI) division, resulted in the immediate suspension of NetNut’s primary web presence. Visitors to the NetNut homepage were greeted by a formal seizure notice stating that the domain had been taken over by the United States government. The notice explicitly acknowledged the contributions of several major industry partners, including Google, Lumen Technologies, and the Shadowserver Foundation, highlighting the collaborative nature of modern cybersecurity enforcement. The disruption is expected to cause significant ripples throughout the residential proxy market, an ecosystem often exploited by threat actors to conduct large-scale automated attacks.
The Nexus Between NetNut and the Popa Botnet
At the heart of the FBI’s investigation is the relationship between NetNut’s commercial proxy services and the Popa botnet. Residential proxies are highly sought after in both the legitimate and illegitimate tech worlds because they allow users to route their internet traffic through the IP addresses of real home users rather than data centers. This makes the traffic appear "organic" and helps it bypass security filters designed to block suspicious activity. However, while some residential proxy services claim to use consensual methods to recruit nodes, the Popa botnet represents a more predatory model.
According to findings released in June 2026 by three distinct security firms, NetNut’s network was largely populated by the Popa botnet. This botnet targets consumer devices—specifically smart TVs, Android-based streaming boxes, and other Internet of Things (IoT) hardware. By embedding malicious software or specialized Software Development Kits (SDKs) into seemingly innocuous applications, the operators of Popa effectively "enrolled" these devices into a global proxy network without the owners’ informed consent. Once infected, these devices became always-on exit nodes for NetNut’s paying customers.
The traffic routed through these compromised devices was frequently tied to abusive and intrusive activities. Security researchers observed the infrastructure being used for massive content scraping operations, sophisticated advertising fraud, and account takeover (ATO) attacks. Because the traffic originated from a residential IP address associated with a legitimate home internet service provider (ISP), it was significantly harder for target websites to identify and block the malicious requests.

Chronology of the Investigation and Takedown
The downfall of NetNut followed a series of escalating revelations regarding the company’s operations and its parent company, Alarum Technologies. The timeline of events suggests a tightening net around the organization throughout 2026:
- January 2026: Synthient, a proxy tracking service, reveals the existence of the "Kimwolf" botnet. Researchers discovered that cybercriminals were tunneling through residential proxy connections to infect additional Android devices behind home firewalls, creating a massive platform for Distributed Denial-of-Service (DDoS) attacks.
- Early June 2026: Google Threat Intelligence Group (GTIG) begins intensive monitoring of suspected NetNut exit nodes. During a single week, they identify 316 distinct clusters of threat actors—ranging from petty cybercriminals to state-sponsored espionage groups—utilizing the infrastructure.
- June 19, 2026: Investigative journalist Brian Krebs and several security firms, including Synthient and Black Lotus Labs (Lumen), publish definitive evidence linking the Popa botnet directly to NetNut and Alarum Technologies.
- Late June 2026: Google takes independent action by disabling Google accounts and services used by NetNut for malware command and control (C2). The tech giant also removes various apps from the Play Store that were found to bundle NetNut’s malicious SDKs.
- July 2026: The FBI and IRS-CI execute the seizure of hundreds of domains, effectively dismantling the backend infrastructure of both the Popa botnet and the NetNut service.
Technical Analysis of Device Compromise
The method by which the Popa botnet expanded its reach is a case study in the vulnerabilities of the modern IoT landscape. Many of the compromised devices were "gray market" TV streaming boxes sold through major e-commerce platforms. These devices often come pre-installed with unofficial versions of the Android operating system that lack Google’s Play Protect certification. To provide access to pirated content—a primary selling point for these boxes—users are often required to install third-party applications that contain the NetNut SDK.
Furthermore, the threat is not limited to off-brand hardware. Research from the proxy tracking firm Spur indicated that a significant percentage of apps available on reputable platforms, such as Samsung’s Tizen and LG’s webOS, also contained these hidden SDKs. Spur’s report found that 42 percent of apps on LG’s webOS and over 25 percent of Samsung’s Tizen apps included components that transformed the television into a residential proxy node.
When a device becomes an exit node, it does more than just relay traffic. It effectively creates a bridge between the open internet and the user’s private local network. Google’s GTIG warned that this allows bad actors to potentially access other private devices on the same home network, such as personal computers, security cameras, or network-attached storage (NAS) devices, exposing them to lateral movement and data theft.
Official Responses and Corporate Fallout
Following the seizure, Alarum Technologies issued a statement through its legal counsel, Omer Weiss. The company maintained a stance of cooperation while acknowledging the gravity of the federal action. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. Despite this cooperative tone, the financial impact on the company was immediate and severe.
In the week following the FBI’s intervention, Alarum Technologies’ stock [NASDAQ: ALAR] plummeted. Trading at approximately $2.62 per share, the stock saw a 67 percent decline, reflecting investor panic and the potential for long-term legal and regulatory repercussions. The seizure of the parent company’s own domain—alarum.io—further signaled that federal investigators were looking beyond just the NetNut subsidiary.

Industry experts believe the takedown will have a lasting impact on the cybercrime economy. Benjamin Brundage, founder of Synthient, noted that NetNut had surged in popularity after the FBI dismantled another major competitor, IPIDEA, earlier in the year. "NetNut was incredibly common among resellers," Brundage explained. "They were on par with IPIDEA in terms of daily traffic, quality, and size. This takedown is going to have a big impact because the community was already reeling from previous losses."
Broader Implications for the Residential Proxy Ecosystem
The NetNut and Popa takedown highlights a growing trend in "whitelabeling" within the proxy industry. Google has expressed high confidence that many popular residential proxy brands do not actually own their own infrastructure but instead buy capacity from networks like NetNut. This means that a single law enforcement action against a primary provider can have a cascading effect, disrupting dozens of "legitimate" proxy resellers who relied on the compromised botnet for their supply.
However, researchers also warn of the ecosystem’s resilience. In the months following the IPIDEA takedown, that service managed to partially rebuild by purchasing capacity from its competitors, effectively turning into a reseller itself. Google’s GTIG emphasized that creating a lasting disruption requires a scaled effort targeting the interconnected infrastructure of multiple providers simultaneously.
For consumers, the advice from cybersecurity experts is clear: hardware security matters. The prevalence of malicious SDKs in streaming apps suggests that users should avoid "jailbroken" or non-certified Android boxes. Sticking to name-brand manufacturers that adhere to Google’s Play Protect standards and being judicious about the installation of third-party apps are essential steps in preventing a home device from becoming a tool for international cybercrime.
As the FBI continues its investigation, the focus will likely shift toward identifying the specific individuals responsible for the development and distribution of the Popa malware. The collaboration between government agencies and private entities like Google and Lumen suggests a new blueprint for tackling botnets—one that combines technical disruption with financial and legal pressure. For now, the millions of devices formerly part of the Popa botnet have been granted a reprieve, though the threat of new networks emerging to fill the vacuum remains a constant concern for the global cybersecurity community.







