In a landmark operation targeting the intersection of corporate proxy services and cybercriminal infrastructure, the Federal Bureau of Investigation (FBI) has successfully seized hundreds of domains associated with NetNut, a prominent residential proxy service operated by the Israeli publicly-traded company Alarum Technologies [NASDAQ: ALAR].
The coordinated takedown, which also involved the Internal Revenue Service (IRS) Criminal Investigation division, marks a significant escalation in law enforcement’s battle against "residential proxy" networks. These networks, often marketed as legitimate business tools for web scraping and market research, have increasingly become the backbone of global cybercrime, providing malicious actors with the ability to route traffic through compromised home devices to mask their origin and bypass security protocols.
The Chronology of a Takedown
The collapse of NetNut was not a sudden event, but the culmination of weeks of intense scrutiny and investigative reporting.
- June 19, 2026: Three independent security firms simultaneously released findings identifying NetNut as the primary engine behind the "Popa" botnet. The reports detailed how NetNut utilized software embedded in home devices—ranging from smart TVs to streaming boxes—to transform them into "always-on" proxy nodes without the explicit or informed consent of the owners.
- Late June 2026: Following the public disclosure, international security researchers and major tech platforms began sharing telemetry data with federal authorities. Google’s Threat Intelligence Group (GTIG) intensified its efforts to track the infrastructure, identifying hundreds of command-and-control (C2) servers.
- July 2026: The FBI and IRS-CI initiated a series of seizures, effectively replacing NetNut’s primary web portals with federal warning banners.
- July 8, 2026: The operation expanded to include the parent company’s primary corporate domain, alarum.io. Following this final blow, Alarum Technologies saw its stock price plummet by roughly 67% in a single week, reflecting the gravity of the legal and operational crisis facing the firm.
Anatomy of the Popa Botnet
At the heart of the controversy is the Popa botnet, a sprawling network estimated to comprise at least two million compromised devices. The mechanism by which NetNut populated this botnet was through the widespread distribution of specialized Software Development Kits (SDKs). These SDKs were often bundled into unofficial, "sketchy" Android streaming boxes or installed via seemingly innocuous applications on smart TV platforms like LG’s webOS and Samsung’s Tizen.
Once installed, these devices ceased to function solely for the user’s entertainment. Instead, they became invisible relays for third-party traffic. When a cybercriminal launched a password-spraying attack, engaged in advertising fraud, or conducted massive content scraping, the traffic appeared to originate from a residential IP address in a victim’s living room. This obfuscation makes it incredibly difficult for security systems to distinguish between a legitimate homeowner and a bad actor.
Google’s investigation revealed that during a single week in June, there were 316 distinct clusters of threat actors utilizing NetNut exit nodes. These actors included sophisticated espionage groups and organized cybercrime syndicates who relied on the service to penetrate private corporate environments.

Official Responses and Corporate Accountability
The response from Alarum Technologies has been one of damage control. Omer Weiss, legal counsel for the firm, issued a statement acknowledging the FBI’s actions. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.
Conversely, the law enforcement and private sector coalition involved in the takedown—including Google, Lumen, and Shadowserver—emphasized the necessity of the operation. Google’s Threat Intelligence Group highlighted the severity of the threat in their post-seizure analysis: "These bad actors can use NetNut to mask their origin IP address when accessing victim environments… effectively exposing [home users] to Internet threats."
Google further confirmed that it has taken proactive steps to disable the Google accounts and services that NetNut used for C2 operations. Additionally, the company has begun purging applications from its ecosystem that were found to be bundling NetNut’s malicious SDKs.
The Ripple Effect: Implications for the Proxy Ecosystem
The takedown of NetNut is viewed by industry experts as a critical victory, yet many warn that the "proxy-as-a-service" market is highly resilient and inherently fluid.
Benjamin Brundage, founder of the proxy tracking service Synthient, suggests that the collapse of NetNut will create a significant vacuum in the cybercrime economy. "NetNut gained significant popularity after the IPIDEA takedown earlier this year," Brundage noted. "They were on par with IPIDEA in terms of daily traffic, quality, and size. This will have a big impact."
However, the "whack-a-mole" nature of the industry remains a primary concern. Google researchers warned that when major operators are disrupted, they often simply transition into resellers, purchasing capacity from smaller, less-scrutinized competitors.

"We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers," the GTIG report concluded. The concern is that the residential proxy model itself—which thrives on the monetization of consumer bandwidth—remains profitable, ensuring that new players will emerge to replace those dismantled by federal authorities.
The Consumer Front: Protecting the Smart Home
The implications of this case extend far beyond corporate boardrooms and federal courts; they strike at the heart of the modern "Internet of Things" (IoT) consumer experience. The ease with which these devices were commandeered highlights a systemic failure in the security standards of home entertainment hardware.
Security analysts, including those at Spur and Synthient, have provided clear guidance to consumers to mitigate these risks:
- Avoid Unofficial Hardware: Avoid "no-name" or low-cost streaming boxes sold on major e-commerce platforms that offer "unlocked" features. These devices frequently come pre-loaded with proxy-enabled firmware that bypasses official security vetting.
- Verify Android TV Certification: Consumers should ensure their devices are certified by Google’s Play Protect. Official Android TV OS devices undergo rigorous security checks that prevent the unauthorized installation of proxy SDKs.
- Audit Smart TV Apps: For users of LG (webOS) and Samsung (Tizen) televisions, the risk is often hidden in third-party applications. Recent research by Spur found that up to 42% of apps on some platforms contained residential proxy components. Users are advised to be highly selective with the applications they install and to remove any software that requests excessive network permissions.
- Network Segmentation: Advanced users are encouraged to isolate IoT devices from the primary network used for banking, work, and personal computing. By placing smart TVs and media boxes on a separate "guest" or isolated VLAN, users can prevent a compromised streaming box from accessing other private devices on the home network.
Conclusion
The dismantling of NetNut stands as a testament to the effectiveness of public-private partnerships in addressing large-scale cyber threats. By severing the connection between the Popa botnet and its primary operator, the FBI and its partners have significantly degraded the capabilities of numerous threat actors.
Yet, the case serves as a stark reminder of the hidden costs of the digital age. As residential proxy networks continue to evolve, the burden of security increasingly shifts to the consumer. In an era where a television can be transformed into a weapon for cyber-espionage or a node in a massive DDoS attack, the mandate for manufacturers, regulators, and users is clear: transparency and security must take precedence over the convenience of an "unlocked" streaming experience. The fall of NetNut is a major blow to the illicit proxy trade, but in the volatile landscape of global cybercrime, it is likely only the beginning of a much longer campaign.
