Executive Overview
In one of the most significant international cybercrime disruptions of the year, the Federal Bureau of Investigation (FBI), in coordination with the Internal Revenue Service Criminal Investigation (IRS-CI) division and key global technology partners, has seized hundreds of internet domains powering NetNut, a massive residential proxy service operated by the publicly traded Israeli enterprise Alarum Technologies (NASDAQ: ALAR).
The coordinated takedown strikes a major blow against Popa, a widespread botnet comprising over two million compromised consumer devices—ranging from unbranded Android set-top boxes to smart televisions—that were silently recruited into NetNut’s proxy network without informed user consent. By leveraging covertly installed Software Development Kits (SDKs) and backdoored firmware, NetNut monetized these infected endpoints by renting out their residential IP addresses to paying customers. While marketed as commercial proxy services for data aggregation, intelligence reports confirm that the network was heavily exploited by cybercriminals, nation-state threat actors, and fraud rings seeking to anonymize malicious internet traffic, orchestrate credential stuffing campaigns, and bypass geographic and security controls.
The law enforcement action follows weeks of mounting scrutiny triggered by investigative findings published by security researchers and tracking firms, which explicitly tied Alarum Technologies’ commercial operations to the illicit Popa botnet. As federal seizure banners replaced the primary domain infrastructure of both NetNut and its parent company, Alarum Technologies suffered a devastating financial fallout, with its stock price collapsing by approximately 67 percent within days of the operation.
+-----------------------------------------------------------------------------------+
| NETNUT / POPA BOTNET TOPOLOGY |
+-----------------------------------------------------------------------------------+
| |
| [ Uncertified TV Boxes ] |
| [ LG webOS Apps ] --+--> [ Embedded Proxy SDKs ] |
| [ Samsung Tizen Apps ] / | |
| v |
| [ Popa Botnet Infrastructure ] |
| | |
| v |
| [ NetNut Reseller / Network ] |
| | |
| +-----------------------------+-----------------------------+ |
| | | | |
| v v v |
| [ Credential Stuffing ] [ Mass Content Scraping ] [ Lateral DDoS Attacks ]
| [ Account Takeovers ] [ Advertising Fraud ] [ (e.g., Kimwolf) ]
| |
+-----------------------------------------------------------------------------------+
Detailed Chronology of the Disruption
1. The Exposé and Initial Research (June 2026)
The downfall of NetNut began in earnest on June 19, 2026, when three independent cybersecurity research organizations—including the proxy-tracking firm Synthient, security firm Spur, and Black Lotus Labs (the threat research arm of Lumen Technologies)—published concurrent technical analyses connecting NetNut’s residential proxy fleet to the Popa botnet.
The security researchers revealed that Popa was not merely a third-party supplier of proxy bandwidth, but effectively the primary engine underpinning NetNut’s enterprise product offerings. Software distributed via sketchy Android applications, pirated media streaming boxes, and rogue smart TV applications contained hidden SDKs that converted victim devices into always-on residential proxy exit nodes. These nodes were then aggregated into NetNut’s network inventory and sold on the open market.
2. The Multi-Agency Takedown Action
Roughly two weeks after the public exposure, federal law enforcement agencies initiated a coordinated operation to dismantle the digital infrastructure supporting NetNut and the Popa botnet.
- Domain Seizures: The FBI and IRS-CI executed court orders to seize control of hundreds of critical domain names used for the command-and-control (C2) operations, telemetry, and administrative portals of NetNut and Popa. Visitors to
NetNut.iowere greeted by a law enforcement seizure banner detailing the multi-agency operation. - Industry Coordination: The operation was executed in close collaboration with private sector partners, including Google, Lumen Technologies, and The Shadowserver Foundation. These entities assisted in sinkholing malicious traffic, neutralizing C2 channels, and identifying compromised endpoints across global networks.
- Platform Mitigation: The Google Threat Intelligence Group (GTIG) acted aggressively within its ecosystem by disabling Google accounts used by NetNut for malicious infrastructure control, terminating applications in the Google Play ecosystem found to contain NetNut’s stealth SDKs, and issuing technical signatures across platform security systems to neutralize the software.
Timeline of Takedown Events (2026)
----------------------------------------------------------------------------------
June 19 Security firms (Synthient, Spur, Black Lotus Labs) publish findings
linking NetNut and Alarum Technologies to the Popa botnet.
Early July FBI and IRS-CI execute domain seizures with support from Google,
Lumen, and Shadowserver; NetNut homepage replaced with seizure notice.
July 8 Alarum Technologies corporate domain (alarum[.]io) exhibits FBI seizure
banner; ALAR stock drops ~67% to $2.62 per share.
----------------------------------------------------------------------------------
3. Corporate Escalation and Financial Impact
By July 8, 2026, the intervention expanded from product-level domains directly to corporate assets. The official corporate domain for Alarum Technologies—alarum[.]io—was seized and replaced with an FBI notice.
The market response was immediate and punishing. Shares of Alarum Technologies (NASDAQ: ALAR), which had already experienced severe volatility following the initial disclosures, plummeted to $2.62 per share—representing a massive 67 percent loss in market value over a single week as investors digested the legal and operational ramifications of the government action.
Supporting Context & Metrics
The Mechanics of Residential Proxy Exploitation
Residential proxies have become the lifeblood of modern cybercrime operations. Unlike traditional datacenter IP addresses, which are easily flagged and blocked by security filters due to their concentration in commercial cloud environments, residential IPs belong to legitimate consumer internet service providers (ISPs).

When malicious actors route traffic through a residential proxy node, security tools perceive the connection as coming from an ordinary household user.
NetNut capitalized on this dynamic by building an architecture powered by compromised consumer hardware:
- Android Streaming Media Devices: Off-brand TV boxes, frequently sold on major e-commerce platforms promising free access to pirated movies and sports, served as prime vectors. These devices often shipped with modified, uncertified Android operating systems containing pre-installed proxy software or hidden SDKs necessary for basic app functionality.
- Smart TV Application Ecosystems: Investigations by proxy intelligence firm Spur demonstrated that stealth proxy SDKs had thoroughly penetrated official smart TV app stores. Spur reported that 42 percent of analyzed applications on LG’s webOS smart TV platform contained embedded residential proxy SDKs. Similarly, more than 25 percent of applications on Samsung’s Tizen operating system contained hidden proxy components.
Once installed, these SDKs turned consumer televisions and streaming boxes into silent, always-on proxy nodes. These endpoints were then abused to route high-volume, malicious web traffic on behalf of paying clients.
Smart TV App Ecosystem Proxy SDK Penetration (Spur Findings)
===================================================================
LG webOS Apps [====================..........] 42% Affected
Samsung Tizen Apps [=============.................] >25% Affected
===================================================================
Threat Actor Usage Metrics
According to technical data published by Google’s Threat Intelligence Group (GTIG), the abuse of NetNut’s infrastructure was far-reaching and systemic. In a single one-week window during June 2026, Google observed 316 distinct threat actor clusters actively routing malicious traffic through suspected NetNut exit nodes.
These groups encompassed a broad spectrum of threat vectors, including advanced persistent threat (APT) espionage actors and financially motivated cybercriminal syndicates. Key activities observed utilizing NetNut infrastructure included:
- Automated Password Spraying and ATO: Routing automated login attempts across thousands of distinct residential IPs to evade rate-limiting controls and execute Account Takeover (ATO) attacks against corporate portals and consumer services.
- Infrastructure Masking: Threat actors utilized NetNut exit nodes to access their own C2 server backends and staging environments, concealing their true geographical location and network origins from law enforcement and threat hunters.
- Massive Web Scraping and Ad Fraud: Bypassing anti-bot protections to perform intrusive data harvesting and automated ad-click fraud.
- Local Network Tunneling and DDoS Attacks: Because residential proxy nodes sit behind home firewalls, malicious actors can leverage them to probe internal networks. In January 2026, Synthient revealed that attackers had weaponized residential proxy connections—specifically through NetNut’s market competitor, IPIDEA—to pivot into local home networks and infect secondary Android devices behind the router. This technique brought about the Kimwolf botnet, which orchestrated record-setting Distributed Denial-of-Service (DDoS) attacks.
Official Statements
Google Threat Intelligence Group (GTIG)
In an analytical report detailing their technical contributions to the law enforcement action, GTIG underscored the systemic security risks posed by consumer-facing residential proxies:
"These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks. Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats."
"Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet… While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller."
Alarum Technologies Corporate Response
Following the initial domain seizures, Omer Weiss, legal counsel for NetNut parent company Alarum Technologies, issued a statement asserting the company’s intent to cooperate with federal authorities:

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account."
Cyber Threat Intelligence Perspectives
Benjamin Brundage, founder of proxy tracking firm Synthient, provided context on the strategic impact of the operation on the cybercrime landscape, particularly in the wake of previous federal enforcement against competing proxy operator IPIDEA:
"I think this takedown is going to have a big impact, because NetNut gained significant popularity after the IPIDEA takedown. Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it."
"In terms of all these TV box devices getting compromised from the proxy network, it will have an impact on the DDoS botnets out there."
Future Outlook & Industry Implications
The Reselling "Hydra" and Network Resilience
While the dismantling of NetNut’s primary domain infrastructure and C2 systems has drastically reduced the pool of available proxy endpoints by millions of devices, security experts caution that the residential proxy market possesses remarkable adaptability.
As demonstrated following the law enforcement action against IPIDEA earlier in the year, proxy providers frequently maintain operational continuity through complex whitelabeling and reselling agreements. When a provider loses its primary botnet infrastructure, it often pivots to purchasing bandwidth wholesale from rival proxy networks, transforming overnight from an infrastructure operator into a proxy reseller.
COMMERCIAL PROXY RESALE CASCADE
[ Primary Botnet / Operator ] (e.g., NetNut / Popa)
|
+--> Whitelabel Partner A --> End User (Cybercriminal)
|
+--> Whitelabel Partner B --> Third-Party Proxy Brand
|
+--> Competitor Inter-B2B Exchange (Bandwidth Leasing)
To achieve permanent deterrence, law enforcement and private sector defenders must continuously target the shared middleman infrastructure, payment processors, and underlying software supply chains that enable disparate residential proxy brands to pool and exchange compromised bandwidth.
Consumer Ecosystem Hygiene and Hardware Risks
The NetNut/Popa action highlights critical vulnerabilities within the Internet of Things (IoT) ecosystem and the consumer smart hardware supply chain. Cheap, uncertified Android TV streaming devices—frequently manufactured by obscure vendors and sold without robust security baselines—have evolved into a primary delivery vector for residential proxy malware.
Security analysts strongly advise organizations and end users to enforce strict hygiene across smart device deployments:
- Stick to Certified Platforms: Consumers should avoid unbranded TV set-top boxes and instead utilize name-brand hardware certified by official platform providers. Devices certified under Google Play Protect undergo continuous security scanning to prevent the installation of unauthorized proxy services.
- Smart TV App Governance: Given the high incidence of stealth SDKs embedded within smart TV software (across LG webOS and Samsung Tizen platforms), users should minimize the installation of obscure, third-party utility applications on smart televisions connected to sensitive home or corporate Wi-Fi networks.
- Network Segmentation: Device owners and network administrators should isolate IoT devices, smart TVs, and streaming boxes on dedicated guest VLANs to prevent compromised proxy endpoints from laterally probing internal networks.
