Operation Proxy Dismantling: FBI and Global Tech Giants Seize Hundreds of Domains Tied to NetNut and the Popa Botnet

Main page Cyber Security & Privacy Operation Proxy Dismantling: FBI and…
From ZizzMedia, the free news encyclopedia
Operation Proxy Dismantling: FBI and Global Tech Giants Seize Hundreds of Domains Tied to NetNut and the Popa Botnet
Operation Proxy Dismantling: FBI and Global Tech Giants Seize Hundreds of Domains Tied to NetNut and the Popa Botnet
Published: 25 August 2026
Author: Iffa Jayyana
Category: Cyber Security & Privacy
Read time: 9 min read
Words: 1,620

Executive Overview

In a sweeping international law enforcement action, the Federal Bureau of Investigation (FBI), alongside the Internal Revenue Service Criminal Investigation (IRS-CI) division and a coalition of premier cybersecurity and industry partners, has seized hundreds of domains tied to NetNut. A sprawling, commercial residential proxy service, NetNut is operated by Alarum Technologies (NASDAQ: ALAR), a publicly traded Israeli tech firm.

The coordinated takedown arrives roughly two weeks after investigative journalist Brian Krebs published independent findings from multiple cybersecurity research firms. These findings explicitly linked NetNut’s proxy architecture to the Popa botnet—a massive collection of at least two million consumer devices compromised by malicious software, typically installed without the explicit, informed consent of the hardware owners.

The disruption has inflicted catastrophic damage on Alarum Technologies. Following the seizure of core corporate domains—including the main company portal at alarum[.]io—the company’s stock price suffered an immediate collapse, plunging roughly 67 percent over the course of a single week to trade at $2.62 per share.

While law enforcement and tech heavyweights like Google and Lumen Technologies are hailing the operation as a monumental blow to cybercriminal infrastructure, security experts warn that the fluid, decentralized nature of the residential proxy ecosystem means threat actors will likely attempt to pivot, white-label, or rebuild under new guises.


Detailed Chronology: From Discovery to Domain Seizures

The unraveling of NetNut’s operations unfolded across a compressed, high-stakes timeline in June and July 2026. The sequence of events highlights how private sector threat intelligence directly fuels federal law enforcement actions.

June 19: The Triple Threat Intelligence Drop

On June 19, three separate cybersecurity and threat intelligence firms independently published synchronized, damning findings. Research from organizations including Synthient and Black Lotus Labs (Lumen) revealed that NetNut was not merely a legitimate commercial proxy provider. Instead, it was functioning as the primary monetization engine for the Popa botnet.

The botnet’s methodology relied on distributing malicious software updates disguised as benign utilities for consumer hardware commonly found in living rooms—specifically smart TVs, Android TV boxes, and streaming hardware. Once installed, the software silently converted these consumer devices into always-on residential proxy nodes. These nodes were subsequently rented out to anonymous third parties, who utilized them to relay intrusive, abusive, and malicious internet traffic, ranging from mass web scraping and ad fraud to coordinated account takeover (ATO) attempts.

Early July: The Digital Hammer Falls

Visitors attempting to access NetNut’s homepage were abruptly greeted by a stark seizure banner emblazoned with the official seals of the FBI and the IRS-CI. The notice confirmed that hundreds of domains associated with the Popa botnet and NetNut’s proxy infrastructure had been seized pursuant to federal warrants.

The takedown notice publicly acknowledged the critical technical assistance provided by private-sector giants and research organizations, including Google, Lumen Technologies, and The Shadowserver Foundation.

By July 8, the enforcement dragnet widened further. The primary corporate website for parent company Alarum Technologies (alarum[.]io) was similarly seized and replaced with federal law enforcement warning banners.


Supporting Context & Metrics: The Mechanics of the Popa Botnet

To fully comprehend the gravity of the FBI’s operation, one must examine the operational mechanics of residential proxy networks and the specific threat posed by the Popa botnet.

FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security

The Anatomy of a Proxy Network

Legitimate residential proxy services route web traffic through residential IP addresses assigned by Internet Service Providers (ISPs), making the traffic appear as though it originates from a normal human user in a specific geographic location. This is often used for legitimate business needs, such as ad verification or localized market research.

However, malicious proxy networks acquire these residential IPs by hijacking consumer devices. According to the Google Threat Intelligence Group (GTIG), NetNut’s infrastructure was heavily sought out by advanced threat actors and cyber espionage groups seeking to obfuscate the origins of their malicious traffic.

In a comprehensive report published concurrently with the takedown, GTIG revealed that during a single week in June 2026, they observed 316 distinct clusters of threat actors utilizing suspected NetNut exit nodes.

"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," GTIG wrote in their analysis. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."

Impact on Smart TVs and Streaming Boxes

The vectors for infecting consumer hardware are deeply embedded in the consumer electronics market. Budget-friendly, unbranded Android TV boxes sold widely on mainstream e-commerce platforms frequently arrive pre-installed with residential proxy software or require the installation of rogue Software Development Kits (SDKs) to function.

Even mainstream consumer hardware is far from safe. A troubling report published by proxy-tracking firm Spur revealed pervasive SDK integration within official app stores for major smart TV brands:

  • LG Smart TVs: Spur discovered that 42 percent of all applications available for download via the webOS operating system included residential proxy SDKs that silently turned the television into an always-on proxy node.
  • Samsung Smart TVs: More than 25 percent of apps developed for Samsung’s Tizen operating system contained similar embedded proxy components.

The Broader Ecosystem and the IPIDEA Precedent

The demise of NetNut follows closely on the heels of another major federal disruption. Earlier in the year, Google’s legal and technical interventions successfully dismantled the infrastructure of NetNut’s primary competitor, IPIDEA.

According to Benjamin Brundage, founder of proxy tracking service Synthient, the takedown of IPIDEA had previously driven a massive surge in NetNut’s popularity.

"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage noted. "Also, NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."

Furthermore, experts point out that these proxy networks act as foundational layers for even more destructive threats. In January, Synthient exposed the Kimwolf botnet, which leveraged tunnel connections through proxy infrastructure like IPIDEA to compromise local networks behind consumer firewalls, turning home streaming boxes into massive Distributed Denial-of-Service (DDoS) engines. The dismantling of NetNut and Popa is anticipated to significantly disrupt these downstream DDoS capabilities.


Official Statements and Corporate Fallout

The response from the corporate entities involved highlights a mix of aggressive technological remediation, legal positioning, and severe financial distress.

FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security

Google’s Technical Countermeasures

Google’s GTIG played an instrumental role in crippling NetNut’s operational backend. In addition to sharing granular technical intelligence regarding NetNut’s SDKs and backend command-and-control servers with law enforcement and research partners, Google executed sweeping platform-level actions:

  • Disabled specific Google accounts and cloud services utilized by NetNut for malware command and control (C2).
  • Delisted and blocked mobile and smart TV applications known to bundle NetNut’s illicit SDKs.
  • Pushed platform-wide mitigations to protect users operating within the official Android ecosystem.

Alarum Technologies Responds

In the wake of the domain seizures, Omer Weiss, legal counsel for NetNut parent Alarum Technologies, issued a written statement acknowledging the government’s actions and pledging institutional cooperation:

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.

Despite these assurances of cooperation, the market reaction was swift and unforgiving. Alarum Technologies stock (NASDAQ: ALAR) plummeted by approximately 67 percent over the tracking week, settling at a valuation of $2.62 per share as investors digested the legal and financial exposure facing the parent company.


Future Outlook: Whitelabeling, Reselling, and the Road Ahead

While Google, the FBI, and private researchers are celebrating a major victory that has degraded NetNut’s proxy network by millions of active devices, cybersecurity veterans urge caution regarding the long-term eradication of the threat.

The residential proxy ecosystem is notoriously fluid. Google’s GTIG report explicitly warns that when major proxy operators face catastrophic infrastructure degradation, they rarely exit the market entirely. Instead, they often pivot to buying capacity from remaining competitors, effectively transforming into underground resellers, or they rebrand and white-label their existing botnets under new corporate shells—much as IPIDEA attempted to do following its earlier disruption.

"What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller," GTIG concluded. "We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."

Recommendations for Consumers and Enterprise Defense

For the average consumer, the revelations surrounding the Popa botnet and smart TV SDK embeddings serve as a stark warning regarding digital hygiene:

  1. Stick to Name Brands: Consumers purchasing Android TV boxes should avoid obscure, unbranded hardware found on discount e-commerce sites. Stick to reputable manufacturers whose devices interface securely with Google’s official Play Protect certification and verified app stores.
  2. Audit Smart TV Apps: Owners of LG and Samsung smart televisions should rigorously review installed applications, removing unnecessary or obscure apps that may harbor hidden proxy SDKs.
  3. Network Segmentation: Enterprises maintaining robust corporate environments should continue to monitor and block residential proxy exit nodes at the perimeter, keeping in mind that threat actors actively leverage these networks to bypass standard geofencing, evade rate-limiting controls, and execute stealthy credential-stuffing attacks.

As law enforcement agencies and tech conglomerates continue to map out the interconnected webs of residential proxy providers, the takedown of NetNut and the Popa botnet stands as a milestone achievement—yet it remains merely one major battle in an ongoing, asymmetric war against commercialized cybercrime infrastructure.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *