In a landmark coordinated operation, the Federal Bureau of Investigation (FBI) has effectively crippled NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli technology firm Alarum Technologies [NASDAQ: ALAR]. By seizing hundreds of domains associated with the platform, federal authorities—supported by the Internal Revenue Service (IRS) Criminal Investigation division—have struck a significant blow against the global cybercrime ecosystem, which has long relied on NetNut’s infrastructure to obfuscate malicious traffic.
This enforcement action comes only two weeks after an investigative report by KrebsOnSecurity, corroborated by multiple leading cybersecurity firms, linked NetNut to the Popa botnet. The Popa network, a massive collection of at least two million compromised devices, has been covertly harvesting residential bandwidth to facilitate illegal activities ranging from mass content scraping and advertising fraud to large-scale account takeover (ATO) attacks.
The Anatomy of the Operation: Chronology and Scope
The collapse of NetNut was not an isolated event but the culmination of a months-long investigation involving a coalition of law enforcement and industry giants, including Google, Lumen, and the cybersecurity research group Shadowserver.
A Timeline of Escalation
- January 2026: Synthient, a proxy tracking service, exposes the "Kimwolf" botnet, revealing how cybercriminals were using proxy tunnels to infect local networks via smart TV streaming boxes.
- Early June 2026: Security firms begin identifying definitive links between the Popa botnet and the NetNut residential proxy network.
- June 19, 2026: Three independent security firms release simultaneous reports detailing how NetNut’s software development kits (SDKs) were turning smart TVs and streaming devices into "always-on" proxy nodes without user consent.
- Early July 2026: The FBI and IRS execute a sweeping seizure of domains linked to the NetNut infrastructure.
- July 8, 2026: The parent company’s primary website, alarum[.]io, is also seized by federal authorities. Following this, Alarum Technologies’ stock price plummeted by roughly 67%, reflecting the catastrophic impact on the firm’s business model.
The seizure notices, which replaced the NetNut homepage, signaled the end of a service that had become a primary choice for threat actors following the earlier dismantling of a major competitor, IPIDEA.
Supporting Data: How the "Popa" Botnet Functions
At the heart of the controversy is the exploitation of the "Internet of Things" (IoT). The Popa botnet functions by distributing malicious software to common household devices—specifically Android-based smart TVs and low-cost streaming boxes. Once infected, these devices are repurposed as residential proxy nodes.
Google’s Threat Intelligence Group (GTIG) provided critical technical insight into this operation. In a blog post released alongside the seizure, Google revealed that in just one week in June 2026, they identified 316 distinct clusters of threat actors—including state-sponsored espionage groups and sophisticated cybercriminals—utilizing NetNut exit nodes.
"These bad actors use NetNut to mask their origin IP address when accessing victim environments," Google reported. "When a consumer device becomes an exit node, unauthorized network traffic passes through it, meaning bad actors can access other private devices on the same home network, effectively exposing them to significant Internet threats."

Furthermore, research from the company Spur has highlighted the vulnerability of modern living rooms. Their analysis found that 42% of apps available on LG’s webOS, and over 25% of apps for Samsung’s Tizen operating system, contained residential proxy SDKs. These SDKs effectively turn televisions into gateways for cybercriminals, often without the owner ever knowing their bandwidth is being monetized by a third party.
Official Responses and Corporate Accountability
The response from Alarum Technologies has been one of damage control. Omer Weiss, legal counsel for the company, acknowledged the FBI seizure and confirmed that the firm is in the process of cooperating with investigators.
"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.
However, industry observers are skeptical of how such a "misuse" could occur on such a massive, systematic scale. Benjamin Brundage, founder of the proxy tracking service Synthient, argues that the business model itself is the problem. "NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, and price per gigabyte," Brundage noted. He suggests that the distinction between a "legitimate" proxy service and a botnet has become entirely blurred in the current market.
Google, for its part, has taken aggressive defensive measures, disabling Google accounts used for malware command-and-control and purging apps that bundle the offending SDKs from their distribution channels.
Broader Implications: A Shifting Cybercrime Landscape
The takedown of NetNut sends a clear message to the residential proxy industry, but experts warn that the ecosystem remains fluid and resilient.
The "Whitelabel" Problem
A recurring theme in the GTIG report is that the residential proxy market is built on a "whitelabel" architecture. Smaller, seemingly independent proxy providers often purchase their bandwidth from larger, "wholesale" networks like NetNut. Consequently, even when one major player is dismantled, the underlying botnet infrastructure often survives, merely shifting to new, smaller providers that buy capacity from the same tainted pools.

"What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller," Google explained. "Creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."
Impact on DDoS and Network Security
The removal of the NetNut/Popa infrastructure is expected to have a tangible impact on the frequency of Distributed Denial-of-Service (DDoS) attacks. Because these botnets are often used to tunnel into local networks, they provide attackers with a foothold behind the victim’s firewall. By neutralizing these proxy networks, law enforcement is not only stopping fraud but also closing backdoors that have been used to assemble massive, decentralized botnets capable of knocking major websites offline.
Consumer Guidance: Protecting the Home Network
For the average consumer, the NetNut saga serves as a cautionary tale regarding the "smart" devices we bring into our homes. The most vulnerable devices are often unbranded, low-cost streaming boxes that run unofficial or modified versions of the Android operating system.
Recommendations for users include:
- Stick to Reputable Brands: Avoid "no-name" streaming boxes that are often sold at suspiciously low prices on major e-commerce platforms. These devices frequently come pre-loaded with proxy SDKs.
- Verify Android Certification: Consumers should ensure their devices are built with official Android TV OS and are certified by Google Play Protect.
- Audit Your Smart TV Apps: Be judicious about the apps installed on Samsung, LG, and other smart TVs. Many free, third-party apps monetize their existence by bundling residential proxy software.
- Network Segmentation: For tech-savvy users, placing IoT devices on a separate VLAN (Virtual Local Area Network) can prevent an infected streaming box from accessing sensitive data on computers or smartphones connected to the same home network.
Conclusion
The FBI’s action against NetNut represents a sophisticated evolution in how law enforcement approaches the infrastructure of cybercrime. By targeting the proxy networks that act as the "plumbing" for digital fraud, authorities are forcing the industry to confront the inherent risks of the residential proxy model.
However, as the market for anonymous, high-speed residential IP addresses remains highly profitable, the battle is far from over. As IPIDEA, NetNut, and others have shown, the digital underworld is adept at pivoting. The long-term success of this initiative will depend on whether regulators and technology platforms can maintain the pressure, forcing a structural change in how proxy services are sourced, verified, and operated. For now, millions of smart devices are safer, and the barrier for entry into the criminal cyber-underworld has been significantly raised.








