In a coordinated strike against the global residential proxy ecosystem, the Federal Bureau of Investigation (FBI), supported by the Internal Revenue Service (IRS) Criminal Investigation division and a coalition of private-sector technology giants, has successfully seized hundreds of domains associated with NetNut. The service, a sprawling residential proxy network operated by the publicly-traded Israeli firm Alarum Technologies [NASDAQ: ALAR], has long been accused of functioning as a conduit for sophisticated cybercriminal activity.
The seizure, which has effectively crippled the infrastructure supporting the massive "Popa" botnet—a collection of at least two million compromised devices—represents one of the most significant enforcement actions against the proxy industry to date.
The Anatomy of the Popa Botnet
The Popa botnet is not a traditional malware cluster. Instead, it is a sophisticated, decentralized network built on the backs of unsuspecting consumers. Research confirms that NetNut’s architecture was designed to repurpose common household electronics—specifically Android-based smart TVs, streaming media boxes, and home gateway devices—into "always-on" residential proxy nodes.
Once infected with the NetNut SDK, these devices become entry points for global traffic. When a client pays to use the NetNut network, their internet traffic is routed through these compromised residential devices. This process obfuscates the true origin of the traffic, allowing cybercriminals to bypass security filters, conduct large-scale ad fraud, perform massive content scraping, and execute account takeover (ATO) attacks while appearing as a legitimate home user.
Chronology of the Investigation and Takedown
The collapse of NetNut was not a sudden event, but the culmination of months of intense scrutiny by cybersecurity researchers and federal investigators.
- January 2026: Security firm Synthient exposes the "Kimwolf" botnet, revealing how criminal actors were tunneling through residential proxy networks to infect devices behind consumer firewalls.
- June 2026: The pressure mounts on the proxy industry. Multiple security firms, including Google’s Threat Intelligence Group (GTIG), publish independent findings on June 19, explicitly linking NetNut to the Popa botnet and confirming its role in distributing malicious software to residential hardware.
- Late June 2026: Following the exposure, Google takes preemptive action, disabling accounts and apps associated with NetNut’s command-and-control infrastructure and sharing technical intelligence with law enforcement.
- July 2026: The FBI and IRS officially seize hundreds of domains, replacing the NetNut homepage with a federal seizure notice.
- July 8, 2026: The crackdown expands. The corporate website for Alarum Technologies (alarum[.]io) is also seized by federal authorities. Alarum stock subsequently craters, losing approximately 67% of its value in a single week.
The Role of Industry Partnerships
The operation was notable for its reliance on "Public-Private Partnership." The FBI’s seizure banner specifically credited Google, Lumen, and the Shadowserver Foundation for providing the technical intelligence necessary to identify and dismantle the sprawling network of command-and-control domains.

Google’s Threat Intelligence Group played a pivotal role, tracking 316 distinct clusters of threat actors using NetNut exit nodes during a single week in June. According to Google, these actors ranged from run-of-the-mill cybercriminals to advanced espionage groups, all utilizing the service to mask their digital footprints. Google’s intervention extended beyond mere domain seizure; the company systematically scrubbed its ecosystem of apps bundling the NetNut SDK, effectively pruning the botnet’s "limbs" by cutting off the software’s distribution channels.
Implications for the Cyber-Proxy Ecosystem
The dismantling of NetNut sends shockwaves through the "Residential Proxy as a Service" market. Benjamin Brundage, founder of the proxy tracking service Synthient, suggests that the takedown of NetNut is arguably more impactful than the previous disruption of its primary competitor, IPIDEA.
"NetNut was on par with IPIDEA in terms of traffic volume, quality, and market penetration," Brundage noted. "Its popularity surged significantly after the IPIDEA takedown, making it a cornerstone for resellers. Seeing it fall leaves a massive void in the cybercrime toolkit."
However, experts warn against premature celebration. The proxy market is notoriously fluid. When one major network is dismantled, operators often pivot, purchasing capacity from smaller, less regulated providers or rebranding themselves as "resellers" of remaining infrastructure. Google’s own internal reports acknowledge this "whack-a-mole" reality, noting that the ecosystem is highly resilient and that long-term success requires sustained, cross-industry pressure.
Official Responses and Corporate Accountability
In the immediate aftermath of the seizures, Alarum Technologies issued a statement through its legal counsel, Omer Weiss. The company acknowledged the FBI action and pledged full cooperation.
"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. Despite this promise of transparency, the company’s market valuation has plummeted, signaling that investors are wary of the long-term legal and regulatory liabilities surrounding the business model.

The Consumer Risk: A Hidden Threat in the Living Room
The most disturbing aspect of the NetNut/Popa affair is the vulnerability of the average consumer. Modern "smart" devices—particularly unbranded Android TV boxes—often arrive pre-loaded with malicious software or require the installation of third-party SDKs to access "free" streaming content.
The security implications are profound. When a device becomes a proxy node, it does not just relay external traffic; it creates a "bridge" into the user’s local network. A device that was intended for watching movies can be used by an attacker to scan for and compromise other devices on the same home Wi-Fi network, including laptops, smart home security cameras, and network-attached storage (NAS) devices.
The Scope of the Problem
A recent study by the security firm Spur highlighted the systemic nature of the threat. Their research found that 42% of apps available for LG smart TVs (via webOS) contained SDKs capable of turning the hardware into a residential proxy. Similarly, over 25% of apps on Samsung’s Tizen OS carried similar risks.
Google has issued clear guidance to mitigate these risks:
- Stick to Reputation: Only purchase streaming hardware from recognized, reputable manufacturers.
- Verify Certification: Ensure that Android-based devices are Google-certified and support Play Protect.
- Audit Your Apps: Be extremely judicious when installing third-party applications, especially those that claim to offer "unlimited" or "free" premium content.
- Official Sources Only: Avoid unofficial operating systems or side-loaded software that bypasses official app stores.
Conclusion: A Turning Point
The FBI-led takedown of NetNut and the Popa botnet represents a critical inflection point in the fight against residential proxy abuse. While the proxy industry will likely attempt to reorganize, the active participation of major technology companies and the increased regulatory scrutiny of publicly traded entities like Alarum Technologies suggest that the "Wild West" era of residential proxy networks is coming to a close.
For the average consumer, the lesson is clear: the convenience of "smart" devices comes with a hidden cost. Without rigorous attention to security and the rejection of unvetted, third-party software, the very devices intended to provide entertainment may be silently serving as the foundation for the next generation of global cybercrime.
