FBI and Industry Partners Dismantle NetNut Residential Proxy Network, Disrupting Popa Botnet

The Federal Bureau of Investigation (FBI), in a significant operation conducted in collaboration with a coalition of industry partners, has successfully seized hundreds of internet domains associated with NetNut, a vast residential proxy service operated by the publicly-traded Israeli company Alarum Technologies (NASDAQ: ALAR). This decisive action, executed on July 8th, follows closely on the heels of investigative findings published approximately two weeks prior by KrebsOnSecurity, which detailed the connection between NetNut and the Popa botnet. The Popa botnet, an expansive network comprised of at least two million compromised devices, has been operating with minimal or no explicit consent from the victims whose devices have been infected with malicious software.
The FBI’s seizure notice, prominently displayed on NetNut’s homepage following the operation, signifies a major blow against a sophisticated infrastructure that has been instrumental in facilitating a range of illicit online activities. The operation also involved the Internal Revenue Service Criminal Investigation division, underscoring the financial and criminal dimensions of the network’s operations. The FBI publicly acknowledged the crucial assistance provided by key industry players, including Google, Lumen, and Shadowserver, for their indispensable role in dismantling the domains tied to the Popa botnet, a network long understood to be synonymous with NetNut’s residential proxy infrastructure.
Genesis of the Investigation and the Popa Botnet
The coordinated action stems from parallel investigations launched by three distinct cybersecurity firms on June 19th. These firms independently reported their findings, all pointing to NetNut’s role as a residential proxy network that directly feeds into the Popa botnet. Their research revealed that NetNut distributes software designed for common household devices, such as smart televisions and streaming boxes. Once installed, this software transforms these everyday devices into continuously operating residential proxy nodes. These nodes are then rented out to a diverse clientele, predominantly comprising individuals and groups engaged in abusive and intrusive internet traffic. Such activities include large-scale content scraping, sophisticated advertising fraud schemes, and unauthorized account takeover operations.
The Popa botnet, at its core, leverages the compromised devices to act as intermediaries, masking the true origin of malicious traffic. This allows threat actors to conduct their operations with a significantly reduced risk of attribution. The sheer scale of the Popa botnet, estimated to include over two million devices, highlights the pervasive nature of this threat and the extensive reach of NetNut’s operations. Each compromised device, unbeknownst to its owner, becomes a potential gateway for cybercriminals to exploit.
Google’s Crucial Role and Analysis
The Google Threat Intelligence Group (GTIG) provided critical insights into NetNut’s operations in a detailed blog post released concurrently with the FBI’s announcement. GTIG’s analysis confirmed that NetNut’s proxy network is not only extensive but also widely resold and white-labeled by numerous third-party proxy providers. This practice effectively obscures the origin of the service and makes it more challenging to track and dismantle. Crucially, Google highlighted that NetNut’s services are highly sought after by cybercriminals precisely because they offer a robust method for obfuscating the source of their malicious activities.
In a single week during June 2026, GTIG observed an alarming 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes. This diverse group included not only cybercriminal organizations but also state-sponsored espionage groups, underscoring the broad spectrum of malicious actors who relied on NetNut’s infrastructure.

"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google’s GTIG stated in their report. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."
Google’s active participation in this disruption extended beyond mere intelligence sharing. The company took direct action by disabling Google accounts and services that were being used by NetNut for command and control of its malicious software. Furthermore, Google disseminated technical intelligence regarding NetNut’s software development kits (SDKs) and backend infrastructure to various platform providers, law enforcement agencies, and other research firms. The company also moved to disable applications known to bundle NetNut’s various SDKs, further disrupting the service’s ability to operate and expand.
Legal Responses and Industry Perspectives
Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, acknowledged the FBI’s seizure and stated that the company is cooperating with the ongoing investigation. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss said in a written statement, signaling a commitment to transparency and accountability.
Benjamin Brundage, founder of the proxy tracking service Synthient, whose company was among those publishing evidence linking the Popa botnet to NetNut and Alarum Technologies last month, offered his perspective on the immediate impact of the domain seizures. Brundage indicated that the operation appears to have significantly disrupted both the Popa botnet itself and the NetNut proxy network that underpins it.
Brundage suggested that the apparent downfall of NetNut will represent a substantial setback for the cybercrime community. This is particularly true given that the community was already contending with the aftermath of legal actions taken by Google earlier in the year, which resulted in the seizure of infrastructure belonging to IPIDEA, NetNut’s primary competitor. "I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage commented. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."
Broader Implications for Cybersecurity and the Residential Proxy Ecosystem
The disruption of NetNut and the Popa botnet is anticipated to have wider-reaching benefits for the cybersecurity landscape. Brundage specifically highlighted the potential reduction in the impact of large distributed denial-of-service (DDoS) botnets. These botnets often rely on poorly configured residential proxy services to achieve their scale and reach. Brundage recalled Synthient’s January revelation concerning the Kimwolf botnet, which was identified as the world’s largest DDoS botnet. This botnet exploited residential proxy connections, including those from IPIDEA, to tunnel into the local networks of TV box owners, subsequently infecting other Android-based devices located behind the victim’s firewall.
While major proxy providers have taken steps to mitigate such activities, Brundage noted that resellers of these networks have been considerably slower to address the emergent threats. "In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there," he stated, implying a positive consequence for online security.

Google itself estimates that the recent actions have inflicted "significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions." However, the company also issued a cautionary note regarding the resilience of proxy networks. They warned that these networks can reconstitute themselves by effectively reselling services from other providers, a strategy observed with IPIDEA in recent months.
"Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet," the GTIG report concluded. "While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."
The Pervasive Threat of Pre-installed and Embedded Proxy Software
The issue of residential proxy software embedded in consumer devices, particularly streaming boxes and smart televisions, remains a significant concern. As KrebsOnSecurity has previously reported, many low-cost Android TV streaming boxes sold on major e-commerce platforms either come pre-installed with residential proxy software or require users to install proxy SDKs to enable their intended functionality. This practice effectively turns unsuspecting consumers into unwitting participants in proxy networks, often without their knowledge or consent.
Google’s advice to consumers remains pertinent: to mitigate risks associated with compromised devices, it is advisable to opt for smart TV boxes from reputable manufacturers with official Android TV OS and Play Protect certification. Users are also encouraged to be judicious about the applications they install on these devices. The sketchy TV boxes that are frequently commandeered by botnets like Popa often run unofficial Android operating systems that bypass Google’s security measures, including the Official Play Protect store. Consumers can verify the authenticity of their device’s operating system by following Google’s official instructions for Android TV OS and Play Protect certification.
The threat is not limited to streaming boxes. Smart televisions from major manufacturers like Samsung and LG can also become enrolled in residential proxy networks through the installation of third-party applications. A recent report by the proxy tracking company Spur found that a significant percentage of apps available on LG’s webOS platform (42%) and Samsung’s Tizen operating system (over a quarter) include SDKs that convert the television into an always-on residential proxy node. This broad integration of proxy technology across various connected devices highlights the pervasive nature of the problem and the challenges faced by consumers in maintaining privacy and security in their digital homes.
Financial Repercussions and Future Outlook
The repercussions of the FBI’s action have been swift and severe for Alarum Technologies. Following the FBI’s announcement and the subsequent seizure notice appearing on its own website, alarum[.]io, the company’s stock price experienced a significant downturn. Reports indicate a roughly 67 percent decline in its stock value over the past week, with shares trading as low as $2.62. This financial impact underscores the seriousness with which the market and regulatory bodies are treating the alleged misuse of the company’s infrastructure.
The dismantling of NetNut and the Popa botnet represents a significant victory for law enforcement and the cybersecurity community. However, as Google’s analysis suggests, the dynamic nature of the residential proxy ecosystem means that the fight against such illicit networks is ongoing. The ability of proxy operators to pivot and rebrand, or to simply purchase capacity from competitors, necessitates a continuous and adaptive approach to cybersecurity enforcement and intelligence sharing. The success of this operation serves as a strong deterrent but also highlights the need for sustained vigilance and collaborative efforts to protect individuals and organizations from the ever-evolving landscape of cyber threats.







