Executive Overview
In one of the most significant law enforcement interventions against commercial proxy abuse to date, the Federal Bureau of Investigation (FBI) and the Internal Revenue Service Criminal Investigation (IRS-CI) division, in coordination with global technology leaders, have seized hundreds of internet domains powering NetNut, a massive residential proxy network operated by the publicly traded Israeli firm Alarum Technologies [NASDAQ: ALAR].
The joint strike—supported by private sector partners including Google, Lumen Technologies’ Black Lotus Labs, and the Shadowserver Foundation—effectively dismantled the core command-and-control (C2) channels of Popa, an illicit botnet estimated to comprise at least two million compromised consumer devices globally.
+-------------------------------------------------------+
| LAW ENFORCEMENT ACTION |
| (FBI / IRS-CI / GTIG / Lumen) |
+---------------------------+---------------------------+
|
v
+-------------------------------------------------------+
| INFRASTRUCTURE TAKEDOWN |
| Seizure of NetNut & Alarum (.io) Domains |
+---------------------------+---------------------------+
|
+----------------------+----------------------+
| |
v v
+-----------------------+ +-----------------------+
| COMMERCIAL RESELLERS | | COMPROMISED ENDPOINTS |
| White-Labeled Proxies | | 2M+ Smart TVs & Set- |
| & Cybercrime Market | | Top Streaming Boxes |
+-----------------------+ +-----------------------+
The enforcement action comes on the heels of deep-dive investigative findings demonstrating that NetNut’s commercial proxy inventory was largely populated by software secretly deployed onto home smart TVs, streaming media boxes, and consumer Internet of Things (IoT) hardware without meaningful user consent. Rented out to third-party subscribers under the guise of legitimate market research and data scraping infrastructure, NetNut’s exit nodes were heavily weaponized by threat actors to execute large-scale account takeover (ATO) attacks, credential stuffing, advertising fraud, and state-sponsored espionage.
The financial and operational fallout for Alarum Technologies has been swift. Following the placement of FBI seizure banners on both NetNut’s operational portals and Alarum’s corporate website (alarum.io), the company’s stock plummeted by roughly 67 percent within a week, dropping to $2.62 per share as investors reacted to the federal seizure and public exposure of its underlying business model.
Detailed Chronology of the Disruption
The downfall of NetNut and the exposure of the Popa botnet represent the culmination of months of coordinated threat tracking, security research, and legal action across the cybersecurity industry and law enforcement.
+-------------------------------------------------------------------------+
| TIMELINE OF EVENTS |
+-------------------------------------------------------------------------+
| [Late 2025] • Security researchers uncover residential proxy SDKs |
| pre-installed on uncertified Android TV boxes. |
| |
| [Jan 2026] • Synthient identifies the "Kimwolf" DDoS botnet |
| exploiting residential proxies to jump home firewalls. |
| |
| [Early 2026] • Law enforcement and Google disrupt IPIDEA, NetNut's |
| primary commercial proxy competitor. |
| |
| [June 19, 2026]• Joint reports published by cybersecurity firms |
| linking NetNut directly to the 2M+ Popa botnet. |
| |
| [Late June 2026]• Google Threat Intelligence Group (GTIG) tracks 316 |
| distinct threat actor clusters using NetNut nodes. |
| |
| [July 2026] • FBI & IRS-CI execute domain seizures; Google revokes |
| associated C2 accounts and infected apps. |
| |
| [July 8, 2026]• Corporate site alarum.io displays FBI seizure banner; |
| ALAR stock collapses ~67% to $2.62 per share. |
+-------------------------------------------------------------------------+
November 2025 – January 2026: The IoT Proxy Epidemic Emerges
Security analysts documented a surge in uncertified, budget Android TV streaming boxes sold on major e-commerce platforms. Telemetry revealed these devices were either pre-loaded with firmware-level proxy software or conditioned to download third-party applications embedding proxy Software Development Kits (SDKs). In January, tracking firm Synthient revealed how threat actors operating the Kimwolf DDoS botnet exploited proxy connections—such as those provided by NetNut competitor IPIDEA—to cross home firewalls, inspect local networks, and infect neighboring smart devices.
Early 2026: Disruption of IPIDEA and Market Migration
Legal and technical operations spearheaded by Google disrupted IPIDEA, then the dominant player in the residential proxy marketplace. This action left a massive vacuum in the commercial proxy sector. NetNut swiftly absorbed IPIDEA’s displaced customer base and traffic volume, scaling its operations to become the primary residential proxy supplier for both commercial clients and underground cybercrime syndicates.
June 19, 2026: Investigative Revelations
Three independent cybersecurity research entities published converging findings establishing that NetNut’s residential proxy pool was fundamentally driven by the Popa botnet. The technical analysis demonstrated that Popa-infected devices—numbering at least two million active nodes—were being monetized through NetNut’s infrastructure, routing traffic through consumer households under the pretense of "ethically sourced" residential IP addresses.
Late June 2026: Threat Intelligence Escalation
The Google Threat Intelligence Group (GTIG) monitored NetNut’s exit node activity, documenting 316 distinct threat actor clusters utilizing NetNut IPs within a single seven-day window. These groups ranged from financially motivated cybercriminals conducting password spraying to sophisticated Advanced Persistent Threat (APT) state-sponsored espionage units masking their location during targeted intrusions.

July 2026: Coordinated Takedown Executed
The FBI and IRS-CI, backed by court orders, seized hundreds of domain names associated with NetNut and the Popa botnet. Google simultaneously executed targeted countermeasures, disabling command-and-control infrastructure within its cloud services, revoking developer accounts, and pulling down applications harboring Popa-linked SDKs from Google Play.
Supporting Context & Technical Metrics
The Architecture of the Popa Botnet and NetNut SDKs
Residential proxy services are designed to route network requests through real residential internet connections, giving buyers access to IP addresses assigned by consumer Internet Service Providers (ISPs). While marketed for legitimate enterprise applications—such as ad verification, price intelligence, and web scraping—the mechanics behind Popa and NetNut relied on forced host monetization.
+-------------------------------------------------------------------------+
| RESIDENTIAL PROXY INFECTION VECTOR |
+-------------------------------------------------------------------------+
| |
| [Consumer Device] <--- App / Firmware with embedded NetNut SDK |
| | |
| v |
| [Background Service] ---> Silently Registers Device as Exit Node |
| | |
| v |
| [NetNut C2 / Proxy Pool] ---> Rents IP to Third Parties & Bad Actors |
| | |
| v |
| [Target Victim] <--- Receives Abusive Traffic (Credential Stuffing, |
| Password Spraying, Mass Scraping, DDoS) |
| |
+-------------------------------------------------------------------------+
- Infiltration via SDKs: Software development kits containing NetNut’s residential proxy routines were bundled into third-party utility applications, media streaming tools, and pirated content software across various smart TV operating systems.
- Silent Execution: Once installed, the host device initialized the SDK in the background upon booting up. Without explicit notice or meaningful user opt-in, the consumer device transformed into an always-on proxy exit node.
- Traffic Tunneling: Cybercriminals purchasing NetNut access routed their internet requests through the victim’s household network. To target websites and security systems, the malicious requests appeared to originate from a legitimate, trusted residential broadband account, bypassing traditional geo-blocking and IP-reputation filters.
- Local Network Exposure: Because the proxy exit node operated from inside the victim’s local area network (LAN), threat actors could potentially route traffic inward, scanning for unpatched routers, local storage units, and other IoT devices sitting behind the home firewall.
Telemetry and Smart TV Vulnerabilities
Data compiled by threat intelligence firm Spur highlights the systemic reliance of residential proxy networks on consumer entertainment devices. According to Spur’s research:
- LG webOS: Approximately 42 percent of analyzed third-party applications available on LG’s webOS smart TV ecosystem contained embedded proxy SDKs designed to turn the television into an active commercial proxy node.
- Samsung Tizen: Over 25 percent of examined applications on Samsung’s Tizen operating system harbored similar background proxy components.
- Uncertified Android TV Set-Top Boxes: Millions of low-cost, unbranded Android TV boxes sold online ship with modified, uncertified open-source Android operating systems that bypass Google Play Protect. These devices often arrive with pre-installed proxy binaries or trick users into downloading compromised software updates.
| Metric / Dimension | Description / Impact |
|---|---|
| Estimated Botnet Footprint | 2,000,000+ active compromised devices globally |
| Observed Threat Clusters (1 Week) | 316 distinct threat actor groups (Criminal + APT Espionage) |
| Parent Company Impact | ~67% stock decline ($2.62/share); core domain (alarum.io) seized |
| Smart TV Ecosystem Exposure | 42% of tested LG webOS apps; >25% of tested Samsung Tizen apps |
Official Statements and Industry Insights
Law Enforcement & Government Action
While federal law enforcement agencies have refrained from commenting beyond the operational details posted directly on seized domains, the official seizure notice published on alarum.io and NetNut endpoints reads:
"This site has been seized by the Federal Bureau of Investigation and Internal Revenue Service Criminal Investigation pursuant to a seizure warrant issued by the United States District Court… in cooperation with international law enforcement and industry partners including Google, Lumen, and Shadowserver."
Google Threat Intelligence Group (GTIG)
In an official statement published alongside the takedown, GTIG outlined the operational impact on threat actors relying on NetNut for operational security:
"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks. Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats.
Our actions have caused significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions."
Parent Company Legal Defense
In response to inquiries regarding the domain seizures and federal intervention, Omer Weiss, legal counsel for NetNut’s parent company, Alarum Technologies, issued a statement asserting corporate compliance:

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account."
Industry Analysis from Synthient
Benjamin Brundage, founder of proxy tracking firm Synthient—which originally exposed the link between Popa and NetNut—emphasized the broader structural impact of the seizure on the cybercrime economy:
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown. NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it.
In terms of all these TV box devices getting compromised from the proxy network, it will have a direct reduction on the scale of DDoS botnets operating across the globe."
Future Outlook & Consumer Protection Framework
The "Hydra Effect" in Residential Proxy Networks
Despite the tactical success of the FBI-led operation, security researchers warn that disrupting residential proxy networks remains an ongoing challenge. Commercial proxy operators frequently adapt to law enforcement actions by restructuring their supply chains.
[ Domain Seizure Executed ]
|
v
[ Operational Degradation of Target Operator ]
|
v
[ Operator Purchases Capacity from Competitors / Resellers ]
|
v
[ Proxy Network Re-emerges under White-Label Architecture ]
When primary proxy pools are dismantled, operators often pivot to purchasing wholesale IP capacity from competing residential networks, acting as white-label resellers to maintain service continuity for paying clients. Achieving lasting disruption across this ecosystem requires sustained, multi-layered operations targeting the underlying app supply chains, app stores, and backend monetization pathways rather than domain infrastructure alone.
Enterprise Defense Recommendations
Organizations aiming to defend against malicious traffic routed through commercial proxy pools should consider the following strategies:
- Behavioral IP Telemetry: Do not rely solely on static IP blocklists. Implement dynamic IP intelligence tools capable of flagging residential IP addresses exhibiting non-residential behavior (e.g., thousands of authentication requests targeting multiple domains per hour).
- Device Fingerprinting: Deploy advanced device fingerprinting to evaluate client characteristics (TLS signatures, browser headers, canvas rendering) to detect discrepancies between reported consumer user-agents and proxy-routed HTTP connections.
- MFA and Rate-Limiting: Enforce risk-based Multi-Factor Authentication (MFA) and aggressive rate-limiting on login endpoints, payment gateways, and registration portals when requests originate from known proxy networks.
Consumer Risk Mitigation Blueprint
For end-users, protecting home networks from turning into proxy nodes requires proactive device management:
- Stick to Certified Hardware: Avoid purchasing unbranded streaming set-top boxes from untrusted online marketplaces. Verify that streaming media hardware carries official Google Play Protect certification.
- Audit Smart TV Apps: Periodically review and uninstall unnecessary applications on Smart TVs (Samsung Tizen, LG webOS, Android TV). Refrain from sideloading APKs or installing unverified software promising free access to copyrighted content.
- Network Segmentation: Isolate Smart TVs, media streaming devices, and IoT hardware on a dedicated guest network or separate Virtual Local Area Network (VLAN). Segregating these devices prevents a compromised endpoint from accessing primary computers, NAS units, or personal devices inside the home network.
