Operation Popa: FBI and Global Tech Giants Dismantle NetNut Residential Proxy Empire Tied to Alarum Technologies

Share
Operation Popa: FBI and Global Tech Giants Dismantle NetNut Residential Proxy Empire Tied to Alarum Technologies

Executive Overview

In a landmark coordinated international law enforcement action, the Federal Bureau of Investigation (FBI)—alongside the Internal Revenue Service Criminal Investigation (IRS-CI) division and critical industry heavyweights including Google, Lumen Technologies, and The Shadowserver Foundation—has seized hundreds of domains associated with NetNut. A sprawling, enterprise-grade residential proxy service, NetNut is operated by Alarum Technologies (NASDAQ: ALAR), a publicly traded Israeli technology company.

The federal takedown arrives roughly two weeks after cybersecurity investigative journalist Brian Krebs published bombshell findings from multiple prominent threat intelligence firms linking NetNut’s infrastructure directly to the Popa botnet. This malicious coalition comprises at least two million consumer devices—predominantly unvetted Android-based streaming boxes and smart TVs—which were hijacked through deceptive software development kits (SDKs) and transformed into always-on proxy nodes without the knowledge or explicit consent of their owners.

The seizure effectively replaces NetNut’s operational web front-ends with official law enforcement warning banners, significantly degrading Alarum Technologies’ corporate valuation and stripping cybercriminal syndicates of one of the world’s most heavily relied-upon conduits for malicious traffic obfuscation. While cybersecurity experts celebrate the blow dealt to the underground economy, threat intelligence agencies warn that the modular and fluid nature of the residential proxy ecosystem means operators will likely attempt to pivot, rebrand, or white-label competing infrastructure to survive.


Detailed Chronology of the Takedown

The collapse of NetNut’s empire is the culmination of months of meticulous digital forensics, multi-agency intelligence sharing, and targeted legal maneuvers designed to decapitate the infrastructure powering modern cybercrime.

The Mid-June Exposé

On June 19, 2026, the cybersecurity community received simultaneous alerts from three independent threat intelligence firms. These reports unmasked the symbiotic relationship between NetNut and the Popa botnet. According to the analyses, NetNut functioned as a commercialized layer masking the mechanics of a massive botnet. The operation distributed intrusive software packaged within applications for everyday consumer hardware—such as cheap streaming sticks and smart TVs—converting these devices into proxy exit nodes. Cybercriminals, state-sponsored espionage groups, and automated threat actors routinely rented these nodes to relay abusive internet traffic, including credential stuffing attacks, large-scale web scraping, and ad fraud.

The Federal Hammer Falls

Following the public disclosure and subsequent escalation by private-sector security partners, federal authorities executed coordinated domain seizures. Visitors to NetNut’s primary web assets were greeted with law enforcement seizure notices issued by the FBI and IRS-CI.

The notices publicly thanked private sector stalwarts—specifically Google, Lumen Technologies’ Black Lotus Labs, and The Shadowserver Foundation—for technical assistance in mapping and disabling hundreds of domains tethered to the Popa botnet infrastructure. The dragnet quickly widened beyond NetNut’s immediate assets; by July 8, the corporate domain for parent company Alarum Technologies (alarum[.]io) also bore the FBI seizure banner as investigators expanded their scope.

Financial and Market Fallout

The regulatory and legal shockwaves instantly reverberated across public markets. Alarum Technologies (NASDAQ: ALAR) absorbed an immediate, catastrophic devaluation. Following the initial domain seizures and the subsequent inclusion of the corporate parent site, Alarum shares plunged precipitously, trading down to roughly $2.62 per share—marking a devastating 67 percent collapse in valuation over a single week.


Supporting Context & Metrics: The Mechanics of Popa and the Proxy Ecosystem

To understand the magnitude of the FBI’s operation, one must examine the mechanics of residential proxy networks and how they are weaponized by threat actors.

FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security

Inside the Popa Botnet

Residential proxies route internet traffic through genuine IP addresses assigned to residential internet service providers (ISPs), making malicious actions appear as though they originate from ordinary home users. Legitimate enterprises utilize proxy networks for market research, web testing, and ad verification. However, criminal ecosystems have weaponized these architectures.

The Popa botnet leveraged consumer devices—primarily uncertified Android TV boxes and smart television operating systems—to build its infrastructure. According to insights published by the Google Threat Intelligence Group (GTIG), NetNut’s network was widely resold and white-labeled by numerous third-party proxy providers, making it a favorite tool for threat actors aiming to bypass IP-based rate limiting and geo-blocking.

GTIG data revealed alarming metrics: in a single week in June 2026, researchers observed 316 distinct clusters of threat actors—spanning financially motivated cybercrime cartels and advanced persistent threat (APT) espionage groups—actively utilizing suspected NetNut exit nodes.

"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," GTIG noted in a technical briefing. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."

The Ripple Effect Across the Underground Economy

Benjamin Brundage, founder of proxy tracking and intelligence firm Synthient—one of the pioneering firms that unmasked the Popa-NetNut connection—noted that the takedown deals a historic blow to the cybercrime underground. This blow is magnified by the fact that the digital underworld was already reeling from Google’s earlier 2026 legal maneuvers against IPIDEA, NetNut’s primary competitor in the residential proxy market.

"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown," Brundage observed. "Also, NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte—all of it."

Furthermore, the disruption of NetNut and Popa is anticipated to curb the spread of massive distributed denial-of-service (DDoS) botnets. Security researchers previously exposed how cybercriminals leveraged unauthorized proxy connections (such as the Kimwolf botnet discovered earlier in the year) to tunnel into local home networks, compromising secondary Android devices sheltered behind domestic firewalls.

Smart TVs and the Ubiquity of Embedded SDKs

The vulnerability is not restricted to obscure streaming boxes purchased on e-commerce marketplaces. Recent research from proxy-tracking firm Spur underscores how mainstream smart television operating systems have become unwitting hosts to proxy infrastructure.

Spur’s audits revealed that:

FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security
  • 42 percent of applications available for download via LG’s webOS smart TV operating system contained SDKs capable of converting televisions into always-on residential proxy nodes.
  • Over 25 percent of apps developed for Samsung’s Tizen operating system harbored similar embedded residential proxy components.

Official Statements and Industry Response

Stakeholders across law enforcement, private tech corporations, and corporate legal departments have issued statements addressing the dismantling of the NetNut infrastructure.

Google Threat Intelligence Group (GTIG)

Google detailed its multifaceted response to the threat, confirming that the company actively intervened across its service ecosystem:

  • Account Deactivations: Google disabled Google accounts and enterprise services utilized by NetNut operators for malware command and control (C2).
  • Information Sharing: Technical intelligence regarding NetNut’s proprietary software development kits (SDKs) and backend routing infrastructure was shared directly with platform operators, law enforcement agencies, and academic research institutions.
  • App Store Enforcement: Applications known to bundle NetNut’s malicious SDKs were purged from official distribution channels.

Despite these wins, Google offered a sobering assessment of the proxy ecosystem’s resilience. GTIG concluded that while the actions degraded millions of nodes, proxy operators routinely adapt by pivoting into white-label resellers of competing infrastructure. "What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller," GTIG warned. "We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers."

Alarum Technologies / NetNut Legal Counsel

Following initial silence, Omer Weiss, legal counsel representing NetNut parent firm Alarum Technologies, issued a formal written statement confirming corporate awareness of the federal seizures and pledging cooperation with investigators:

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.


Future Outlook: Securing the Consumer Frontier

The joint federal and private-sector takedown of NetNut and the Popa botnet marks a monumental victory for global cybersecurity, temporarily blinding numerous cybercriminal syndicates and dismantling a multi-million-node residential proxy apparatus. However, experts emphasize that the war against illicit proxy networks is far from over.

Cybercriminals have proven adept at recreating proxy capacity through multi-tiered reselling models, shifting operations to offshore jurisdictions, and exploiting unpatched or unsecured consumer IoT devices.

Actionable Defense Recommendations for Consumers

To protect domestic networks from being co-opted into illicit botnets and proxy networks, security researchers and major tech platforms recommend the following best practices:

  1. Stick to Name Brands: When purchasing Android TV boxes, streaming sticks, or smart home appliances, consumers should exclusively buy from reputable, well-known manufacturers. Avoid unbranded or white-label hardware sold via third-party e-commerce platforms.
  2. Verify Play Protect Certification: Consumers should verify that their Android devices operate within Google’s official Play Protect ecosystem. Unofficial builds often bypass security constraints, leaving systems vulnerable to silent software modifications.
  3. Audit Smart TV Applications: Users should exercise discretion when downloading applications onto LG (webOS) and Samsung (Tizen) smart televisions, reviewing app permissions and avoiding obscure utility apps that request unnecessary background network access.
  4. Network Segmentation: Where possible, isolate Internet-of-Things (IoT) devices, streaming boxes, and smart TVs onto a separate guest VLAN or isolated Wi-Fi network, preventing compromised home hardware from pivoting to sensitive personal computers or network-attached storage (NAS) devices.

As law enforcement agencies and tech giants refine their collaborative playbooks to target interconnected proxy infrastructure, the dismantling of NetNut serves as a stark warning to technology firms operating in the gray areas of digital data routing: the legal and operational liabilities of harboring cybercriminal traffic are rapidly catching up to profitability.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *