In a sweeping cross-border law enforcement operation, the Federal Bureau of Investigation (FBI) has successfully seized hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly traded Israeli firm Alarum Technologies [NASDAQ: ALAR]. The operation, which also involved the Internal Revenue Service (IRS) Criminal Investigation division, marks a significant escalation in the ongoing crackdown against "proxy-as-a-service" providers that facilitate cybercrime by masking the origins of malicious internet traffic.
The takedown follows a wave of investigative scrutiny, most notably a series of reports from security researchers that exposed NetNut’s symbiotic relationship with the Popa botnet. The botnet, a massive web of at least two million compromised devices—ranging from smart televisions to low-cost streaming boxes—had been repurposed into a clandestine relay network. By turning household electronics into "always-on" proxy nodes, the operators behind NetNut enabled cybercriminals to launch sophisticated attacks while evading detection by traditional security filters.
The Anatomy of the Operation
The seizure was not a unilateral effort but a coordinated strike involving a coalition of public and private entities. Alongside the FBI and IRS-CI, technical infrastructure support was provided by tech giants and security firms, including Google, Lumen, and Shadowserver.
Visitors to the NetNut homepage today were greeted not by the company’s marketing materials, but by a stern government seizure notice—a visual testament to the severity of the allegations. The operation targeted the core infrastructure of the service, effectively severing the connection between the malicious actors renting the proxies and the millions of residential devices unknowingly acting as their "exit nodes."
A Chronology of the Collapse
The downfall of NetNut was preceded by months of meticulous investigation and public disclosure:
- Early 2026: Security researchers at Synthient and other firms begin documenting the rise of the Popa botnet, noting its unusual ability to infiltrate local area networks through compromised Android-based streaming devices.
- June 19, 2026: Three independent security firms release simultaneous reports linking the Popa botnet directly to NetNut’s infrastructure. The reports detail how NetNut’s software development kits (SDKs) were being embedded into pirated or "grey-market" streaming hardware.
- Late June 2026: Google’s Threat Intelligence Group (GTIG) publishes a scathing analysis, confirming that NetNut services were being used by over 300 distinct clusters of threat actors, including sophisticated espionage groups.
- July 2026: The FBI and IRS-CI execute the domain seizures, rendering the service’s primary portals inaccessible.
- July 8, 2026: The parent company’s primary website, alarum[.]io, is also seized. Market reaction is swift; Alarum Technologies’ stock price plummets by approximately 67% over the course of a week, closing at $2.62 per share.
The "Popa" Connection: How Household Devices Became Weapons
At the heart of the controversy is the concept of the "residential proxy." In theory, these services allow legitimate businesses to conduct market research or ad verification by routing traffic through home IP addresses, which are less likely to be blocked than data-center IPs. In practice, however, NetNut’s infrastructure was weaponized.

The Popa botnet functioned by infecting devices—predominantly budget-tier Android TV boxes—with malicious software. These devices were then "rented out" through the NetNut platform. When a hacker or fraudster wanted to conduct a password-spraying attack, engage in advertising fraud, or scrape proprietary content, they would route their traffic through these unsuspecting home devices.
The consequences for the device owners were severe. Not only did the devices suffer performance degradation, but by serving as an exit node, the internal networks of these homes were effectively opened to the outside world. This meant that malicious actors could potentially pivot from the compromised TV box to attack other sensitive devices on the same home network, such as laptops, smartphones, or smart home security cameras.
Official Responses and Corporate Accountability
The reaction from the industry and the involved parties has been one of both relief and caution. Google, which played a pivotal role in the technical disruption, emphasized that the cleanup effort involved not just disabling proxy domains but also purging apps from their ecosystem that bundled the malicious NetNut SDKs.
"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google’s GTIG wrote in an official statement. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."
Alarum Technologies, through its legal counsel Omer Weiss, has attempted to mitigate the fallout. In a statement released shortly after the seizure, Weiss noted: "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account."
Implications for the Proxy Ecosystem
The demise of NetNut is expected to create a significant power vacuum in the illicit proxy market. Benjamin Brundage, founder of the proxy tracking service Synthient, noted that the takedown is likely to have a "big impact" precisely because NetNut had become the go-to provider following the earlier disruption of its main competitor, IPIDEA.

"NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, and price," Brundage explained. However, the ecosystem remains inherently fluid. Security experts warn that while this strike is a major victory, the "whitelabeling" nature of these services means that many smaller, "no-name" proxy brands are simply re-selling access to the same underlying botnet infrastructure.
Google’s intelligence report underscores this resilience: "What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller." This suggests that a permanent fix will require broader, industry-wide standards for how these proxy networks are sourced and audited.
The Consumer Front: Protecting the Smart Home
Perhaps the most alarming takeaway from the NetNut investigation is the pervasiveness of proxy SDKs in modern consumer electronics. Research from the firm Spur indicates that this is not limited to cheap, obscure streaming boxes. Their analysis revealed that 42% of apps available on LG’s webOS, and over 25% of apps on Samsung’s Tizen operating system, contained components that could turn a television into an active proxy node.
For consumers, the advice from cybersecurity experts is clear:
- Stick to Reputable Hardware: Avoid "no-name" Android streaming boxes purchased from third-party marketplaces. These devices often ship with pre-installed malware or unofficial operating systems that bypass the security checks of the official Google Play Store.
- Audit Your Apps: Be highly selective about the applications installed on smart TVs. If an app provides "free" access to paid content (like movies or sports), it is highly likely to be monetizing the user’s device as a proxy node.
- Check Certification: Ensure that Android-based devices are Google Play Protect certified. Consumers can verify this status through official Google support documentation.
Conclusion: A Turning Point?
The takedown of NetNut and the associated Popa botnet represents a major milestone in the fight against the weaponization of the Internet of Things (IoT). By targeting the financial and operational pillars of these proxy networks, law enforcement is making it increasingly difficult—and costly—for cybercriminals to hide their tracks.
However, as long as there is demand for anonymous, residential-grade IP addresses, the market for these services will likely persist in one form or another. The challenge for the future, according to researchers, is to move beyond "whack-a-mole" tactics and toward systemic reforms that hold the manufacturers of smart devices accountable for the security—and the integrity—of the software running on their products. For now, the millions of devices previously enslaved to the Popa botnet can breathe a temporary sigh of relief, but the shadow cast by the proxy industry continues to loom large over the connected home.
