By Global Cybersecurity & Technology Desk
Updated: July 8, 2026
Executive Overview
In a sweeping multinational law enforcement action, the Federal Bureau of Investigation (FBI)—alongside the Internal Revenue Service Criminal Investigation (IRS-CI) division and an array of private-sector cybersecurity partners—has successfully seized hundreds of domains tied to NetNut, a sprawling residential proxy service operated by the publicly traded Israeli technology firm Alarum Technologies (NASDAQ: ALAR).
The coordinated takedown follows intense scrutiny from security researchers and industry intelligence groups that linked NetNut’s commercial proxy operations directly to the Popa botnet. This malicious infrastructure has quietly hijacked an estimated two million consumer devices—ranging from inexpensive smart TVs and streaming boxes to everyday home internet routers—without the explicit consent of their owners.
The dismantling of NetNut’s command-and-control (C2) and infrastructure domains marks a catastrophic blow to a major player in the illicit proxy market. For years, cybercriminal syndicates, state-sponsored espionage groups, and malicious automated actors relied heavily on NetNut to obfuscate their digital footprints, mask origin IP addresses, bypass rate limits, and carry out large-scale credential-stuffing and password-spraying attacks.
While the action has crippled a vital artery in the global cybercrime supply chain, security experts warn that the fluid ecosystem of residential proxy networks remains resilient. Operators frequently pivot by white-labeling competitor services or migrating underground, signaling that long-term mitigation will require sustained, multi-layered defensive strategies across hardware manufacturers, application stores, and law enforcement agencies.
Detailed Chronology: From Investigative Exposés to Federal Seizures
The collapse of NetNut’s digital empire did not happen overnight; rather, it was the culmination of converging intelligence reports from independent security firms, major tech conglomerates, and federal investigators.
The June 2026 Exposés
On June 19, 2026, three separate cybersecurity intelligence firms published concurrent findings exposing a direct operational bridge between commercial residential proxy provider NetNut and the Popa botnet. The reports detailed how NetNut distributed software development kits (SDKs) and applications—frequently bundled into cheap, uncertified Android streaming devices and unauthorized apps—that transformed consumer hardware into always-on proxy nodes.
Rather than functioning as a standard, consented bandwidth-sharing network, NetNut’s infrastructure acted as an active relay for abusive internet traffic. Third-party renters of the proxy network utilized these residential IPs to engage in automated web scraping, ad fraud, and targeted account takeovers, exposing ordinary households to external security intrusions.
The Enforcement Hammer Drops
Roughly two weeks after these technical disclosures, users navigating to NetNut’s primary web portals were greeted by an ominous law enforcement seizure banner. The notices, emblazoned with the insignia of the FBI and IRS-CI, confirmed that federal authorities had seized hundreds of domains associated with the Popa botnet and NetNut’s underlying infrastructure.
The banners explicitly thanked crucial private-sector partners—including Google, Lumen Technologies’ Black Lotus Labs, and the Shadowserver Foundation—for providing the forensic telemetry, threat intelligence, and sinkhole capabilities required to execute the operation.

The ripple effects of the legal actions quickly reverberated through corporate channels. By July 8, the corporate web portal for Alarum Technologies (alarum[.]io) also fell to the federal seizure campaign. Consequently, investor confidence plummeted, sending Alarum Technologies stock into a tailspin. Shares shed approximately 67 percent of their value over a single week, trading at a dismal $2.62 per share as markets reacted to the legal exposure.
Supporting Context & Metrics: The Mechanics of the Popa Botnet and White-Label Proxies
To fully grasp the scale of the FBI’s operation, one must understand how modern residential proxy networks operate and why they have become such a lucrative cornerstone of the modern cybercrime economy.
The Anatomy of a Proxy Network
Residential proxy services allow customers to route web traffic through real residential IP addresses assigned to everyday consumers by Internet Service Providers (ISPs). Legitimate use cases exist, such as market research, ad verification, and geo-testing. However, cybercriminals prize these proxies because traffic originating from a residential IP looks indistinguishable from a legitimate human user, effectively bypassing anti-fraud systems, web application firewalls (WAFs), and rate-limiting controls.
NetNut scaled its proxy network by embedding software components into consumer-facing devices. According to the Google Threat Intelligence Group (GTIG), NetNut’s infrastructure was widely resold and white-labeled across a sprawling ecosystem of smaller, underground proxy brands. In June 2026 alone, GTIG telemetry identified 316 distinct clusters of threat actors—including financially motivated cybercriminals and advanced persistent threat (APT) espionage groups—actively routing malicious traffic through NetNut exit nodes.
Collateral Damage to Home Networks
When a consumer device is co-opted into becoming an active proxy node, it opens a dangerous bidirectional tunnel into the victim’s local network. Unauthorized third-party traffic passes directly through the device, exposing other private connected equipment—such as networked storage drives, smart home appliances, and personal computers—to external threats.
Furthermore, researchers note the alarming convergence of proxy networks and Distributed Denial-of-Service (DDoS) botnets. Earlier in the year, proxy-tracking service Synthient exposed how operators leveraged proxy connections to tunnel into local networks, turning compromised TV boxes into vectors for massive DDoS botnets like Kimwolf. While primary network operators occasionally curb such behavior, underground resellers of proxy bandwidth have historically lagged in enforcing safety protocols, leaving millions of smart home devices vulnerable.
Smart TVs and Uncertified Streaming Boxes
The vector for infection often starts at the point of purchase. Millions of consumers buy inexpensive, unbranded Android TV boxes through major e-commerce platforms. These devices frequently arrive pre-loaded with malicious residential proxy software or require users to sideload apps that bypass Google’s official Play Protect security architecture.
Even mainstream smart television owners are not immune. A comprehensive June 2026 study by proxy-monitoring firm Spur revealed that 42 percent of applications available for download via the webOS operating system on LG smart TVs contained SDKs capable of converting televisions into always-on residential proxy nodes. Similarly, over 25 percent of apps developed for Samsung’s Tizen operating system harbored parallel proxy components, highlighting a pervasive supply-chain vulnerability within the smart display industry.
Official Statements and Industry Response
The collapse of NetNut has drawn sharp commentary from the technology sector, legal counsel, and threat intelligence analysts alike.
Google’s Threat Intelligence Assessment
In a detailed technical blog post published alongside the law enforcement action, the Google Threat Intelligence Group outlined the aggressive countermeasures taken by the tech giant. Google confirmed that it actively disabled Google accounts and services utilized by NetNut for malware command-and-control operations. Additionally, the company shared comprehensive telemetry regarding NetNut’s SDKs and backend architecture with platform providers, academic researchers, and law enforcement agencies while purging offending applications from its ecosystem.

Despite achieving significant degradation of NetNut’s business operations—effectively cutting off millions of devices from the proxy pool—Google issued a sober warning regarding the adaptability of the cybercrime underground:
"While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."
Alarum Technologies’ Legal Response
In the wake of the federal seizures, Omer Weiss, legal counsel for NetNut parent company Alarum Technologies, issued a written statement acknowledging the government’s actions and pledging institutional cooperation:
"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account."
Perspectives from Threat Intelligence Analysts
Benjamin Brundage, founder of proxy tracking service Synthient—one of the foundational firms that publicly tied the Popa botnet to Alarum Technologies—emphasized the profound shockwaves this takedown will send through the criminal underworld.
According to Brundage, NetNut’s sudden demise follows closely on the heels of Google’s legal actions earlier in the year against IPIDEA, NetNut’s chief market rival. With both market titans dismantled or severely crippled in rapid succession, the underground proxy market faces an unprecedented supply crunch.
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage observed. "Also, NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte—all of it."
Future Outlook: The Path Forward for Consumer Security
While the joint operation by the FBI, IRS-CI, Google, and Lumen represents a watershed moment in the global fight against commercialized cybercrime, industry experts stress that dismantling infrastructure is only half the battle.
Cybercriminal syndicates have repeatedly demonstrated an agile capacity to reconstitute operations, shifting away from exposed brands toward stealthy white-label networks or entirely decentralized architectures. Consequently, security experts advocate for a multi-tiered defense strategy encompassing regulatory pressure, platform hygiene, and consumer vigilance:
- Hardware Procurement Standards: Consumers are strongly advised to avoid unbranded, deeply discounted streaming boxes sold on major online marketplaces. Purchasing certified hardware from reputable, established manufacturers ensures adherence to strict operating system security standards and compatibility with official application storefronts like Google Play Protect.
- Application Auditing: Smart TV owners should exercise extreme caution when downloading utility, streaming, or media-sharing applications on platforms running webOS or Tizen. Minimizing the installation of unverified third-party software dramatically reduces the risk of introducing residential proxy SDKs into home environments.
- Cross-Industry Collaboration: As demonstrated by the collaborative triumph of the NetNut takedown, neutralizing systemic threats requires continuous intelligence sharing between hyper-scalers, telecommunications infrastructure providers, and law enforcement agencies. Only by systematically targeting interconnected reseller ecosystems can international authorities hope to impose enduring friction on the cybercrime economy.
As federal investigations continue and financial fallout mounts for Alarum Technologies, the message to the residential proxy industry is unmistakably clear: the era of operating vast, unconsensual botnets under the guise of legitimate commercial proxy services is drawing to a close.
