FBI and Global Tech Coalition Dismantle NetNut and Popa Botnet in Major Blow to Cybercrime

Share
FBI and Global Tech Coalition Dismantle NetNut and Popa Botnet in Major Blow to Cybercrime

Executive Overview

In a sweeping international law enforcement operation, the Federal Bureau of Investigation (FBI)—alongside the Internal Revenue Service Criminal Investigation (IRS-CI) division and a coalition of global technology giants—has seized hundreds of domains tied to NetNut, a sprawling residential proxy service operated by the publicly traded Israeli firm Alarum Technologies (NASDAQ: ALAR).

The coordinated takedown strikes directly at the infrastructure of the Popa botnet, a massive collection of over two million consumer devices compromised by malicious software with little or no consent from their owners. These devices—predominantly smart TVs, streaming boxes, and connected home appliances—were covertly transformed into always-on residential proxy nodes. Cybercriminals, state-sponsored espionage groups, and malicious actors routinely rented these nodes to mask their digital footprints, route abusive traffic, conduct mass web scraping, execute ad fraud, and launch credential-stuffing campaigns.

The action represents the second major blow delivered to the global residential proxy underground in 2026, following similar legal maneuvers against competitor IPIDEA earlier in the year. Industry experts view the dismantling of NetNut as a landmark disruption, though security researchers warn that the fluid, hyper-adaptive nature of the proxy ecosystem means threat actors will likely attempt to pivot, rebrand, or white-label alternative infrastructure in the months to come.


Detailed Chronology: From Security Disclosures to Federal Seizures

The collapse of NetNut’s operational infrastructure is the culmination of a high-stakes convergence between independent threat intelligence researchers and federal law enforcement agencies.

The June Exposé

The writing on the wall began to appear in mid-June 2026. On June 19, three independent cybersecurity firms simultaneously released coordinated research findings exposing a direct link between NetNut’s commercial residential proxy network and the Popa botnet.

The researchers detailed how NetNut distributed software development kits (SDKs) and applications—frequently bundled into unverified streaming tools—to devices commonly found in modern living rooms. Once installed, these applications quietly turned consumer hardware into proxy exit nodes. This routing architecture allowed third-party renters to channel malicious internet traffic directly through domestic IP addresses, effectively weaponizing everyday broadband connections against their will.

The Federal Takedown

Barely two weeks after these technical disclosures rattled the cybersecurity community, the crackdown materialized. Visitors to NetNut’s primary web portals were greeted not by commercial offerings, but by an official seizure banner emblazoned with the seals of the FBI and IRS-CI.

The forfeiture notice formally acknowledged critical collaborative support from prominent industry partners, including Google, Lumen Technologies’ Black Lotus Labs, and the Shadowserver Foundation. By targeting the domain infrastructure underpinning both Popa and NetNut, law enforcement effectively severed the critical command-and-control (C2) pathways connecting the proxy network to its captive device pool.

The fallout rapidly expanded beyond NetNut’s immediate assets. By early July, the corporate domain for parent company Alarum Technologies (alarum.io) was also seized by the FBI, bringing the corporate and operational front ends under federal control. The swift regulatory and legal action triggered an immediate crisis for the publicly traded company; Alarum Technologies stock plummeted, trading at approximately $2.62 per share—representing a catastrophic 67% valuation collapse over the course of a single week.


Supporting Context & Metrics: The Mechanics of the Popa Botnet

To understand the severity of the FBI’s intervention, one must examine the sheer scale and utility of residential proxy networks within the modern threat landscape.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Google Threat Intelligence Group Findings

In a comprehensive technical report published concurrently with the domain seizures, the Google Threat Intelligence Group (Google GTIG) laid bare how cybercriminals weaponized NetNut’s infrastructure. According to Google, NetNut’s services were widely resold and white-labeled across the dark web and underground forums, making it a preferred choice for threat actors seeking absolute anonymity.

Google GTIG analysts revealed staggering telemetry data: during a single week in June 2026, researchers observed 316 distinct clusters of malicious threat actors actively routing traffic through suspected NetNut exit nodes. This roster included financially motivated cybercriminal syndicates as well as advanced persistent threat (APT) state-sponsored espionage groups.

"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," Google’s GTIG team wrote in their advisory. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."

Google’s Remediation Actions

Recognizing the depth of the integration, Google executed broad defensive operations:

  • Account Terminations: Google disabled specific Google accounts and backend services utilized by NetNut operators to manage malware C2 frameworks.
  • App Purges: The tech giant systematically removed mobile applications and streaming tools known to bundle NetNut SDKs from official distribution channels.
  • Information Sharing: Google distributed granular technical intelligence regarding NetNut’s proprietary SDKs and backend infrastructure to platform operators, global law enforcement agencies, and academic research institutions.

The Smart TV and Streaming Box Epidemic

The vulnerability is not isolated to obscure hardware. While cheap, unbranded Android TV boxes purchased on major e-commerce platforms have long been flagged for pre-installed proxy software or mandatory SDK integrations, mainstream consumer hardware is also heavily impacted.

A glaring exposé published last month by proxy intelligence firm Spur revealed alarming statistics regarding smart TV operating systems:

  • LG Smart TVs: Spur discovered that 42 percent of all applications available for download via the webOS operating system contained software development kits designed to convert televisions into always-on residential proxy nodes.
  • Samsung Smart TVs: More than one-quarter (25%) of applications built for Samsung’s Tizen operating system harbored similar residential proxy components.

This means millions of everyday consumers who purchased household-name smart televisions unknowingly exposed their home local area networks (LANs) to external manipulation.


Official Statements and Industry Reactions

The law enforcement action has reshaped the proxy market dynamics, prompting reactions from legal representatives, threat hunters, and specialized infrastructure analysts.

Alarum Technologies Responds

Following initial media inquiries, Omer Weiss, legal counsel representing NetNut parent company Alarum Technologies, issued a carefully worded statement acknowledging the federal actions and pledging compliance:

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Perspectives from Proxy Tracking Experts

Benjamin Brundage, founder of proxy tracking and intelligence service Synthient—one of the pioneering firms that originally published evidence linking Popa to Alarum Technologies—noted that the takedown leaves a massive vacuum in the cybercrime underground.

Brundage emphasized that NetNut’s collapse follows closely behind Google’s earlier legal actions against rival proxy network IPIDEA. Because NetNut absorbed much of the displaced market share left by IPIDEA’s demise, its sudden removal deals a compounding blow to threat actors who relied on its reliability, price-per-gigabyte metrics, and extensive daily traffic volume.

"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage observed. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."

Furthermore, Brundage highlighted an ancillary victory: the potential suppression of massive Distributed Denial-of-Service (DDoS) botnets. In January, Synthient exposed the Kimwolf botnet—the world’s largest DDoS botnet at the time—which operated by tunneling through IPIDEA proxy connections to compromise secondary Android devices residing behind consumer firewalls. With NetNut and Popa dismantled, the underlying vectors for propagating secondary local network infections are significantly blunted, though downstream resellers remain a persistent headache.


Future Outlook: Whitelabeling, Resilience, and Consumer Defense

While federal authorities and Google celebrated the degradation of NetNut’s operational capacity—cutting off millions of devices from the proxy operator’s pool—industry analysts urge caution against premature declarations of total victory.

The Hydra-Headed Nature of Proxy Networks

Google GTIG’s post-disruption analysis underscored the resilient, highly adaptable mechanics of the residential proxy economy. When major infrastructure providers face legal degradation or domain seizures, operators rarely exit the market entirely. Instead, they pivot to a whitelabeling model, purchasing capacity wholesale from smaller, less conspicuous competitors or mutating into underground resellers.

"While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient," Google’s GTIG report concluded. "What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."

Recommendations for Consumers and Enterprise Defenders

Security researchers emphasize that protecting against residential proxy abuse requires vigilance at both the consumer and corporate layers:

  1. Exercise Caution with Streaming Hardware: Consumers are strongly advised to avoid unbranded, white-label Android TV streaming boxes sold on major e-commerce marketplaces unless they explicitly verify that the device runs official Android TV OS certified by Google Play Protect. Instructions for verifying device certification can be found via official Google support channels.
  2. Audit Smart TV Applications: Given that a significant percentage of apps on LG and Samsung app stores contain hidden proxy SDKs, users should meticulously audit installed applications, remove unverified utility or streaming apps, and restrict unnecessary network permissions.
  3. Enterprise Defense Strategies: Security operations centers (SOCs) and threat hunters must continue updating intelligence feeds to detect residential proxy exit nodes. Because threat actors leverage these networks to mimic legitimate residential traffic during credential stuffing and lateral movement, traditional IP blacklisting based solely on data center ranges is no longer sufficient; defenders must incorporate continuous behavioral analysis and proxy-detection databases into their perimeter defenses.

As federal investigations continue and financial fallout mounts for Alarum Technologies, the NetNut takedown stands as a watershed moment in the ongoing war against commercialized cybercrime infrastructure. However, as the digital underground adapts to law enforcement pressures, the battle to reclaim consumer hardware from predatory botnet operators remains an evolving frontier.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *