In a sweeping coordinated operation, the Federal Bureau of Investigation (FBI), alongside the Internal Revenue Service’s Criminal Investigation division (IRS-CI), has seized hundreds of domains linked to the residential proxy service NetNut. The service, a cornerstone of the residential proxy market, was operated by the publicly traded Israeli firm Alarum Technologies [NASDAQ: ALAR].
This decisive action marks a significant escalation in the war against "residential proxy networks"—infrastructure that allows cybercriminals to route malicious traffic through the home IP addresses of unsuspecting consumers, effectively masking the origin of illegal activities. The operation was bolstered by critical technical support from tech giants and security firms, including Google, Lumen, and Shadowserver, all of whom have been tracking the integration of NetNut’s infrastructure with the notorious Popa botnet.
The Anatomy of the Popa Botnet
At the center of the controversy is the Popa botnet, a sprawling collection of at least two million compromised devices. Security researchers have long identified Popa as the engine powering NetNut’s residential proxy network. The botnet primarily exploits "Internet of Things" (IoT) hardware—specifically low-cost Android-based smart TVs and streaming boxes.
Once infected, these devices are transformed into "always-on" proxy nodes. This transformation occurs without the meaningful consent of the device owners. Once a device is under the control of the NetNut/Popa infrastructure, it is leased to third-party clients who utilize the bandwidth for a range of illicit purposes, including high-volume content scraping, advertising fraud, and large-scale account takeover (ATO) attacks.
A Chronology of the Investigation
The takedown follows a period of intense scrutiny from the cybersecurity community. The timeline of events leading to the seizure reveals a rapid escalation in both intelligence gathering and regulatory response:
- Mid-2025: Security researchers begin identifying a spike in unauthorized traffic originating from low-cost streaming devices, identifying the early stages of what would later be termed the "Popa" phenomenon.
- January 2026: Synthient, a proxy tracking firm, exposes the "Kimwolf" botnet, which utilized similar proxy-tunneling techniques to infiltrate local networks through poorly configured Android-based streaming boxes.
- June 19, 2026: Three separate security firms release simultaneous reports linking NetNut directly to the Popa botnet, providing forensic evidence that the company was distributing software that compromised home-based hardware.
- Early July 2026: Following these revelations, the FBI and IRS-CI move to seize the digital infrastructure supporting the network.
- July 8, 2026: The investigation widens; the official corporate website for Alarum Technologies (alarum[.]io) is seized by federal authorities. Market confidence in the firm collapses, with shares plunging approximately 67% to $2.62.
The Role of Tech Giants: Google’s Intelligence Analysis
The Google Threat Intelligence Group (GTIG) played a pivotal role in the takedown. In a detailed post-operation analysis, Google confirmed that NetNut’s network was not only used by independent bad actors but was also "white-labeled" by other proxy providers. This meant that cybercriminals could purchase access to the NetNut infrastructure through various third-party storefronts, further obfuscating their identities.
Google’s investigation discovered that in a single week in June 2026, 316 distinct clusters of threat actors were actively leveraging NetNut exit nodes. These actors included sophisticated cybercriminal syndicates and state-sponsored espionage groups.

"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google noted in its report. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."
To mitigate the damage, Google has taken the unprecedented step of disabling the specific Google accounts used for malware command and control and purging apps from their ecosystem that were found to be bundling NetNut’s Software Development Kits (SDKs).
Official Responses and Corporate Accountability
The fallout from the seizure has placed Alarum Technologies in a defensive posture. Omer Weiss, legal counsel for the firm, issued a statement shortly after the seizure, acknowledging the gravity of the situation.
"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated. Despite this pledge of cooperation, the seizure of the corporate domain suggests that federal investigators are looking beyond mere "misuse" and into the fundamental design of the service.
Wider Implications for the Proxy Ecosystem
Industry experts believe the disruption of NetNut will have a profound ripple effect. Benjamin Brundage, founder of Synthient, suggests that the market was already reeling from the previous takedown of IPIDEA—a primary competitor to NetNut.
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage said. "NetNut was incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, and price per gigabyte."
However, there is a cautionary note in the industry: the "reseller" nature of these networks makes them resilient. When one major provider is dismantled, the operators often pivot, buying capacity from competitors and shifting their business model to become a reseller of other, still-active, illicit networks.

Google’s GTIG warned that while the current operation has significantly degraded the available pool of compromised devices, the ecosystem is inherently fluid. "We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers," the group concluded.
The Consumer Risk: Smart TVs and "Sketchy" Hardware
The investigation has shone a harsh spotlight on the consumer electronics market. A significant portion of the botnet is comprised of "no-name" streaming boxes sold on major e-commerce platforms. Many of these devices come pre-loaded with proxy software or require the user to install unofficial operating systems to access pirated content.
These devices often bypass Google’s "Play Protect" certification, leaving them vulnerable to exploitation. The issue is not limited to cheap streaming boxes; even major television brands are implicated. Research by the security firm Spur found that 42% of applications on LG’s webOS and over 25% of applications on Samsung’s Tizen operating system contained SDKs that could potentially turn a smart TV into an always-on residential proxy node.
How Consumers Can Protect Themselves:
- Stick to Reputable Brands: Avoid "no-name" Android TV boxes that are not Play Protect certified.
- Verify Certification: Use Google’s support resources to check if your device is officially certified.
- Audit App Installations: Be judicious about the apps installed on smart TVs. If an app is not from a reputable, known developer, it may be bundling hidden proxy SDKs.
- Network Hygiene: Use a firewall to monitor for unusual outbound traffic from IoT devices. If a smart TV is communicating with unknown servers at 3:00 a.m., it may be acting as a proxy node.
Conclusion: A Turning Point
The FBI’s seizure of NetNut is a watershed moment in the battle against residential proxy abuse. By disrupting the primary conduit for the Popa botnet, authorities have provided temporary relief to millions of compromised home networks. However, the persistence of these proxy networks, which continue to evolve through white-labeling and reseller tactics, suggests that the fight is far from over.
As the digital landscape becomes increasingly cluttered with "smart" devices, the responsibility of securing these endpoints is shifting from the end-user to the manufacturers and the regulators. Until the industry addresses the underlying issue of proxy-ready SDKs being embedded in consumer hardware, the threat of one’s living room being used as a weapon in a global cyberattack remains a stark reality.
