Federal Bureau of Investigation Dismantles NetNut Residential Proxy Network, Disrupting Global Cybercrime Operations

The Federal Bureau of Investigation (FBI), in a robust and coordinated effort with key industry partners, today announced the successful seizure of hundreds of domains linked to NetNut, a vast residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. This significant law enforcement action follows critical revelations published by KrebsOnSecurity and findings from multiple cybersecurity firms, which conclusively connected NetNut to the notorious Popa botnet, a sprawling network comprising at least two million consumer devices covertly compromised by malicious software, often without the owners’ knowledge or explicit consent. This coordinated strike represents a major blow against a critical piece of global cybercrime infrastructure, designed to obscure illicit online activities and exploit unsuspecting users worldwide. The immediate consequence of this operation was the replacement of NetNut’s homepage with a prominent seizure banner from the FBI, signaling the definitive disruption of its operations.
Understanding Residential Proxy Networks and the Botnet Threat
To fully grasp the gravity and implications of the FBI’s expansive operation, it is essential to delve into the intricate nature of residential proxy networks and the sinister role botnets play in the modern cyber threat landscape. A residential proxy network leverages legitimate, unique IP addresses assigned by Internet Service Providers (ISPs) to residential homes. These are distinct from datacenter proxies, which are typically easier to identify and block due to their concentrated origins. The inherent legitimacy and distributed nature of residential IP addresses make them highly attractive to both legitimate businesses seeking geographically diverse access and, more alarmingly, to cybercriminals aiming for enhanced anonymity and evasion. Legitimate applications might include market research, content localization testing, or brand protection, where a company needs to view web content as if originating from a specific geographic location. However, a darker, more pervasive side emerges when these networks are built upon unwittingly compromised devices.
NetNut, through its underlying Popa botnet, epitomized this illicit application. The service operated by deploying malicious software, frequently embedded within popular consumer electronics such as smart TVs and streaming boxes. This surreptitious installation transformed these devices into "always-on" residential proxy nodes, essentially converting them into unwilling participants in a vast, rented network. These nodes were subsequently leased to clients, predominantly to facilitate abusive and intrusive internet traffic. The spectrum of illicit activities enabled by NetNut’s infrastructure was extensive and damaging, encompassing large-scale content scraping—where vast amounts of proprietary data are illegally extracted from websites—sophisticated advertising fraud schemes designed to siphon ad revenue, and complex account takeover attacks targeting financial institutions and personal online accounts. By routing their malicious traffic through millions of diverse, legitimate residential IP addresses, cybercriminals could effectively mask their true origin, making detection, attribution, and subsequent legal action incredibly challenging for cybersecurity defenders and law enforcement agencies. The sheer scale of the Popa botnet, with over two million compromised devices, underscored the pervasive reach and potential for harm inherent in such operations. Each compromised device, from a smart television to a streaming dongle, became an unwitting participant in a global network of digital deception, its resources silently siphoned off for criminal gain and its security posture severely undermined.
A Detailed Chronology of Exposure and Disruption
The successful takedown of NetNut was not an overnight event but rather the culmination of diligent investigative work, public exposure, and robust public-private collaboration that unfolded over several critical weeks and months.
June 19, 2026: The Initial Revelations and Public Warning
Approximately two weeks prior to today’s coordinated seizure, a series of independent but strikingly convergent investigations brought NetNut’s illicit operations into sharp, public focus. On June 19, three distinct cybersecurity firms—including Synthient, a specialized proxy tracking service, and Lumen Technologies’ Black Lotus Labs—published comprehensive findings. These detailed reports unequivocally established NetNut as a residential proxy network directly connected to the Popa botnet. The firms meticulously documented how NetNut’s software infected devices commonly found in homes, such as smart TVs and streaming boxes, systematically transforming them into proxy nodes. These nodes, as highlighted by the security research, were then exploited to relay a broad spectrum of malicious internet traffic, including mass content scraping, advertising fraud, and sophisticated account takeover attempts. Brian Krebs, through his influential security blog KrebsOnSecurity, played a pivotal role in synthesizing and disseminating these findings to a wider public audience, amplifying the urgency and severity of the threat. His consistent reporting on such illicit networks had laid groundwork for understanding their operational models and impact.
Early July 2026: The Coordinated Seizure and Law Enforcement Action
Earlier today, the tangible consequences of these revelations materialized dramatically across the internet. Visitors attempting to access NetNut’s homepage were met not with the company’s usual interface, but with a stark, unmistakable seizure notice prominently displayed by the FBI and the Internal Revenue Service Criminal Investigation (IRS CI). The direct involvement of the IRS CI underscored the significant financial implications of such large-scale illicit operations, indicating potential investigations into illicit gains, money laundering, tax evasion, or other financial crimes stemming from the widespread misuse of the proxy service. The seizure banner explicitly acknowledged and thanked key industry partners—Google, Lumen, and Shadowserver, among others—for their invaluable assistance in dismantling the hundreds of domains tied to the Popa botnet. This public acknowledgment highlighted the critical role of private sector intelligence, technical expertise, and collaborative efforts in modern, complex cybercrime investigations that span international borders.
Google’s Proactive Measures and Strategic Intelligence Sharing
In parallel with the direct law enforcement action, Google’s Threat Intelligence Group (GTIG) released a detailed blog post providing further insights into NetNut’s operations and Google’s own extensive efforts to combat it. GTIG’s research revealed that NetNut’s proxy network was extensively resold and white-labeled by numerous third-party proxy providers, making its services a prime choice for cybercriminals seeking to obfuscate their malicious traffic. The sheer scale of this illicit adoption was staggering: GTIG observed 316 distinct clusters of threat actors, encompassing both financially motivated cybercriminal syndicates and sophisticated state-sponsored espionage groups, utilizing suspected NetNut exit nodes within a single week in June 2026 alone. This data painted a clear and alarming picture of NetNut’s pervasive integration into the global cybercrime ecosystem.

Google’s response extended beyond mere observation and analysis. The tech giant actively disabled Google accounts and services identified as being used by NetNut for malware command and control (C2) operations, effectively severing vital communication links for the botnet. Furthermore, Google shared critical technical intelligence regarding NetNut’s proprietary software development kits (SDKs) and backend infrastructure with a wide array of platform providers, law enforcement agencies, and research firms. This proactive intelligence sharing is crucial for a unified and effective defense against such sophisticated and rapidly evolving threats. The company also took decisive action to disable applications known to bundle NetNut’s various SDKs, directly impacting the botnet’s ability to proliferate and recruit new unwitting participants.
Alarum Technologies’ Official Response and Significant Financial Repercussions
In the immediate wake of the seizure, Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, issued a public statement confirming the company’s awareness of the FBI action and pledging full cooperation with investigators. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. This corporate response indicated an attempt to distance the publicly traded parent company from the alleged illicit activities, while acknowledging the severe operational impact and the necessity of compliance.
The financial market, however, reacted swiftly and negatively to the news. In a telling update, the corporate website for Alarum Technologies itself, alarum[.]io, also began displaying an FBI seizure notice, further solidifying the direct impact on the parent company. The company’s stock experienced a precipitous decline, trading at $2.62 a share, representing a roughly 67 percent decrease over the week following the FBI action. This significant and immediate financial impact underscores the severe operational and reputational consequences for publicly traded entities found to be facilitating, however unwittingly, large-scale cybercrime.
The Pervasive Threat of Popa and Similar Botnets
The Popa botnet’s reach extended far beyond merely providing anonymous proxy services. As Google’s GTIG elucidated, when a consumer device becomes an exit node for such a network, it exposes the entire home network to severe security risks. "Unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats," GTIG warned. This aspect of the compromise transforms an individual device infection into a potential gateway for broader home network breaches, jeopardizing personal data, smart home devices, and other connected systems, potentially leading to identity theft or further malware propagation.
Benjamin Brundage, founder of Synthient, one of the companies that published crucial evidence linking Popa to NetNut and Alarum Technologies, confirmed the immediate efficacy of the domain seizures. Brundage noted that the action appeared to have successfully disrupted both the Popa botnet and the NetNut proxy network that relied upon it. He emphasized the significant blow this represented to the cybercrime community, particularly considering their prior reliance on NetNut for obfuscating malicious traffic.
Brundage further contextualized NetNut’s prominence by linking it to an earlier disruption in the illicit proxy market. He explained that NetNut had experienced a surge in popularity and market share following Google’s legal actions earlier this year against IPIDEA, another major residential proxy provider. "I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage stated. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it." This highlights the dynamic, often cutthroat, and highly adaptable nature of the illicit proxy market, where one provider’s downfall can quickly lead to another’s ascent, as criminal enterprises seek to maintain their operational capabilities.
The impact of the NetNut and Popa botnet takedown extends to other types of cyber threats as well, particularly large distributed denial-of-service (DDoS) botnets. Brundage pointed out an alarming trend Synthient uncovered in January, revealing how cybercriminals had constructed the Kimwolf botnet, one of the world’s largest DDoS botnets, by exploiting IPIDEA proxy connections. These attackers effectively tunneled through the proxy connections into the local networks of TV box owners, subsequently infecting other Android-based devices behind the victim’s firewall to expand their DDoS capabilities. While some larger, more reputable proxy providers had taken steps to block this specific type of activity, resellers often lagged significantly in implementing similar protections, leaving a critical vulnerability. "In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," Brundage predicted, suggesting a positive ripple effect on the overall DDoS threat landscape by reducing the pool of easily exploitable devices.
The Broader Implications and Future Challenges in Cybercrime Disruption
Google’s assessment of today’s actions confirmed a "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." While this is undoubtedly a substantial victory in the fight against cybercrime, Google also sounded a cautionary note regarding the inherent resilience and adaptability of illicit proxy networks. These sophisticated services have demonstrated a remarkable ability to rebuild, often by diversifying their offerings or reselling other proxy services, as observed with IPIDEA’s activities in the months following its initial disruption.

The GTIG report concludes with a stark warning that points to the interconnected nature of the illicit proxy ecosystem: "Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet." This implies that the problem is deeply integrated and widespread, with numerous seemingly independent services potentially drawing from the same compromised device pool. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers." This statement from Google underscores the ongoing cat-and-mouse game between law enforcement and cybersecurity defenders and the highly sophisticated operators of these malicious networks, emphasizing the critical need for sustained, broad-based, and internationally coordinated efforts to achieve long-term impact.
Consumer Vigilance: A Critical Defense Layer Against Compromise
The revelations surrounding NetNut and Popa also serve as a critical wake-up call for consumers about the security of their smart devices and the potential for covert exploitation. As KrebsOnSecurity has consistently warned, many inexpensive, no-name TV streaming boxes readily available on major e-commerce platforms often come either pre-installed with residential proxy software or require the installation of specific proxy SDKs to function as intended (e.g., streaming pirated movies, sporting events, or TV shows). The allure of cheap entertainment often comes with a hidden and significant cost: unwittingly turning one’s personal device into an active node in a criminal network, sacrificing privacy and security.
Google’s advice is unequivocal and prudent: consumers should prioritize name brands from reputable manufacturers when purchasing TV boxes and exercise extreme caution and judiciousness with any apps they choose to install. The sketchy TV boxes implicated in the Popa botnet and similar threats typically run unofficial, modified Android operating systems that bypass Google’s Official Play Protect store, a crucial security safeguard designed to vet applications for malware. Google provides clear instructions for consumers to verify if a device is built with the official Android TV OS and Play Protect certification, empowering users to make more informed and secure purchasing choices.
The problem, however, extends beyond just obscure, low-cost streaming boxes. Even mainstream smart TVs from major manufacturers like Samsung and LG are not entirely immune to this form of compromise. A recent report from the proxy tracking company Spur highlighted a startling statistic: 42 percent of apps available for download via the webOS operating system on LG smart TVs were found to include SDKs capable of transforming the television into an always-on residential proxy node. Similarly, over a quarter of apps designed for Samsung’s Tizen operating system contained comparable residential proxy components. This widespread embedding of such SDKs across the smart TV ecosystem indicates a systemic vulnerability, making consumer awareness and careful app selection paramount. The convenience and integration of smart features must always be carefully weighed against the potential security risks inherent in a vast, interconnected digital landscape where malicious actors are constantly seeking new vectors for exploitation.
Conclusion: A Continuing Battle for Internet Integrity and User Safety
The FBI’s decisive action against NetNut and the Popa botnet marks a significant victory in the ongoing, complex fight against global cybercrime. It unequivocally demonstrates the growing effectiveness and necessity of public-private partnerships in identifying, investigating, and ultimately dismantling sophisticated malicious infrastructure. By disrupting a network responsible for facilitating myriad forms of fraud, exploitation, and privacy invasion, law enforcement has dealt a substantial blow to the operational capabilities of cybercriminals globally, forcing them to re-evaluate their tactics and seek alternative, less robust infrastructure.
However, the cautionary warnings from Google and experienced cybersecurity researchers like Benjamin Brundage are a sobering reminder that this battle is far from over. The inherent adaptability and resilience of illicit proxy networks necessitate a continuous, multi-pronged approach. This includes relentless law enforcement pressure, sustained and enhanced intelligence sharing among cybersecurity firms and leading tech companies, and crucially, vastly improved consumer education. As more devices become "smart" and interconnected components of our daily lives, the collective responsibility of securing the digital environment increasingly falls on every user. The NetNut takedown is a powerful testament to what can be achieved through coordinated collaboration, but it also serves as a clarion call for continued vigilance and proactive measures to safeguard the integrity of the internet and protect individuals from covert digital exploitation. The pursuit of those who exploit the digital infrastructure for criminal gain remains a top priority for global security agencies, requiring a sustained, adaptive, and collaborative response.







