In one of the most significant law enforcement actions against commercial residential proxy networks to date, the Federal Bureau of Investigation (FBI), in coordination with the Internal Revenue Service Criminal Investigation (IRS-CI) division and international tech leaders, has seized control of hundreds of web domains associated with NetNut. The sprawling residential proxy enterprise is owned and operated by Alarum Technologies [NASDAQ: ALAR], a publicly traded Israeli cybersecurity and privacy firm.
The international operation came just weeks after investigative reports and technical analyses from multiple cybersecurity firms explicitly linked NetNut’s commercial proxy inventory to Popa, a massive, covert botnet comprising at least two million compromised consumer devices. The targeted infrastructure, which spanned smart TVs, set-top streaming boxes, and home networking hardware, operated with little to no consent from device owners, transforming everyday household electronics into exit nodes for illicit cyber activity.
+-----------------------------------------------------------------------------------+
| NETNUT / POPA BOTNET ARCHITECTURE |
+-----------------------------------------------------------------------------------+
| |
| [ Uncertified Android Boxes ] [ Smart TV Apps ] [ Malicious Firmware/SDKs ] |
| | | | |
| +------------------------+------------------------+ |
| | |
| v |
| [ Popa Botnet (2M+ Compromised Devices) ] |
| | |
| v |
| [ NetNut Residential Proxy Network ] |
| | |
| +---------------------------------+---------------------------------+ |
| | | | |
| v v v |
| [ Cybercriminal Groups ] [ Espionage Operators ] [ White-Label Resellers ] |
| (Password Spraying, Fraud) (Traffic Obfuscation) (Third-Party Services) |
| |
+-----------------------------------------------------------------------------------+
Executive Overview
The joint takedown marks a critical juncture in the global effort to neutralize residential proxy networks—a segment of the internet infrastructure that has increasingly blurred the line between legitimate commercial services and organized cybercrime. Residential proxies allow users to route their internet traffic through genuine home IP addresses, making bad actors appear to web services and fraud detection systems as typical household consumers.
While commercial proxy providers often claim their services are intended for legitimate enterprise uses like market research, ad verification, and search engine optimization, technical telemetry revealed that NetNut’s backbone relied heavily on the Popa botnet. Devices were routinely infected via sketchy third-party firmware, pirated streaming applications, and compromised software development kits (SDKs).
=================================================================================
TAKEDOWN METRICS
=================================================================================
• Compromised Exit Nodes Disrupted: 2,000,000+ devices
• Distinct Threat Groups Observed: 316 active clusters (in a single week)
• Parent Company Market Value Loss: ~67% stock decline following domain seizure
• Key Smart TV Ecosystem Exposure: 42% of LG webOS apps (per Spur report)
>25% of Samsung Tizen apps
=================================================================================
The fallout for NetNut’s parent company, Alarum Technologies, has been immediate and catastrophic. Following the seizure of NetNut’s primary operational domains, federal authorities extended domain control to Alarum’s corporate website (alarum[.]io). In the days following the law enforcement action, Alarum’s stock plummeted by roughly 67 percent, trading down to $2.62 per share as Wall Street reacted to the unraveling of the company’s core revenue driver.
Detailed Chronology of the Disruption
The dismantling of NetNut and the Popa botnet unfolded through a sequence of private-sector threat disclosures, infrastructure interventions, and law enforcement actions.
+-----------------------------------------------------------------------------------+
| CHRONOLOGY OF EVENTS |
+-----------------------------------------------------------------------------------+
| |
| [ Late 2025 - Early 2026 ] |
| • Security researchers trace Kimwolf DDoS botnet to residential proxy tunnels. |
| • Initial mapping of uncertified Android TV streaming box compromises. |
| |
| [ June 19, 2026 ] |
| • Synthient, Black Lotus Labs (Lumen), and independent researchers release |
| joint disclosures linking NetNut directly to the Popa botnet. |
| • KrebsOnSecurity publishes an exposé detailing Alarum Technologies' tie to Popa.|
| |
| [ Late June 2026 ] |
| • Google Threat Intelligence Group (GTIG) tracks 316 threat clusters on NetNut. |
| • Google takes down C2 accounts, revokes SDK-linked apps, and notifies partners. |
| |
| [ Early July 2026 ] |
| • FBI & IRS-CI execute federal domain seizures targeting NetNut and Popa C2s. |
| • NetNut homepage replaced with federal seizure notice. |
| • Alarum Technologies legal counsel releases public statement confirming |
| cooperation with law enforcement. |
| |
| [ July 8, 2026 ] |
| • FBI extends seizure banner to corporate domain alarum[.]io. |
| • Alarum Technologies [NASDAQ: ALAR] stock crashes ~67% to $2.62 per share. |
| |
+-----------------------------------------------------------------------------------+
Unmasking the Architecture
On June 19, 2026, research released by proxy-tracking intelligence firm Synthient, alongside Black Lotus Labs (the threat research arm of Lumen) and independent security analysts, established a direct technical chain of custody between NetNut’s commercial proxy pipeline and Popa. The findings demonstrated that NetNut was not merely purchasing excess bandwidth from willing participants, but was operating directly on top of malware-infected consumer hardware distributed worldwide.
Private Sector Countermeasures
Armed with this telemetry, major technology organizations initiated coordinated backend mitigation. The Google Threat Intelligence Group (GTIG) intervened by neutralizing Google platform accounts and command-and-control (C2) channels utilized by NetNut operators. Google disabled applications found to be silently embedding NetNut SDKs and shared intelligence detailing the network’s backend infrastructure with security research communities, platform providers, and law enforcement agencies.
Federal Domain Seizures
By early July, the FBI and IRS-CI executed federal court orders seizing hundreds of domains critical to NetNut’s operational continuity. Visitors to NetNut’s public-facing domains were greeted with an official law enforcement banner acknowledging technical assistance from Google, Lumen, The Shadowserver Foundation, and other industry partners. Days later, federal authorities seized alarum[.]io, effectively severing the publicly traded parent company from its digital public presence.

Supporting Context & Technical Metrics
To understand the scope of the NetNut/Popa infrastructure, one must examine how residential proxy networks operate and how threat actors exploit them.
The Anatomy of a Parasitic Proxy Network
Unlike datacenter proxies—which utilize IP addresses registered to cloud providers and are easily identified and blocked by security filters—residential proxies utilize IP addresses assigned by Consumer Internet Service Providers (ISPs). When a cybercriminal routes traffic through a residential exit node, the target server perceives the connection as originating from an ordinary homeowner.
+-----------------------------------------------------------------------------------+
| COMMERCIAL PROXY VS. PARASITIC BOTNET |
+-----------------------------------------------------------------------------------+
| Legitimate Residential Proxy Model: |
| [ User ] ---> [ Explicit Consent / Opt-In App ] ---> [ Paid Bandwidth Sharing ] |
| |
| Parasitic NetNut / Popa Model: |
| [ User ] ---> [ Pirated App / Uncertified OS ] ---> [ Silent SDK Hijack ] |
| | |
| v |
| [ Uncompensated Node ] |
| | |
| v |
| [ Malicious Traffic Tunnel ] |
+-----------------------------------------------------------------------------------+
NetNut populated its network primarily by inserting stealth software development kits into consumer electronics. The primary vectors included:
- Uncertified Streaming Devices: Budget Android TV boxes sold via online marketplaces often come pre-loaded with modified operating systems that run residential proxy client services out of the box.
- Piracy-Focused Applications: Streaming apps designed to access unauthorized media routinely condition service functionality on the background execution of proxy SDKs.
- Smart TV App Ecosystems: Unsuspecting developers integrate proxy SDKs into standard smart TV applications to monetize their free software, often failing to disclose the full scope of background network activities to end users.
Smart TV Ecosystem Vulnerabilities
Data from proxy intelligence firm Spur highlighted how deeply embedded these proxy SDKs have become within smart television app stores. Spur’s analysis revealed alarming infection rates across top smart TV platforms:
- LG webOS: Approximately 42 percent of available applications audited contained embedded SDKs capable of converting the television into an always-on residential proxy node.
- Samsung Tizen: More than 25 percent of evaluated applications contained similar residential proxy components.
Once installed, these SDKs turn the TV or set-top box into a permanent operational relay. Because smart TVs are rarely turned off completely and remain connected to local Wi-Fi networks continuously, they serve as ideal infrastructure for proxy operators.
+-----------------------------------------------------------------------------------+
| SMART TV ECOSYSTEM INFECTION RATES (SPUR DATA) |
+-----------------------------------------------------------------------------------+
| |
| LG webOS Apps [======================= 42% =======================] |
| |
| Samsung Tizen Apps [============== 25%+ ==============] |
| |
+-----------------------------------------------------------------------------------+
Threat Actor Exploitation and Threat Landscape
The impact of NetNut’s proxy pool on the broader cybersecurity threat landscape was immense. In a single week during June 2026, Google Threat Intelligence Group observed 316 distinct threat actor clusters utilizing suspected NetNut exit nodes. These actors ranged from financially motivated cybercrime syndicates to state-sponsored espionage groups.
+-----------------------------------------------------------------------------------+
| PRIMARY MALICIOUS USES OF NETNUT PROXIES |
+-----------------------------------------------------------------------------------+
| • Credential Stuffing & Password Spraying: Masking login attempts to bypass |
| automated rate-limiting and geolocation rules. |
| • E-Commerce Fraud & Web Scraping: Harvesting proprietary data and carrying out |
| automated checkout abuse. |
| • Lateral Network Pivoting: Tunneling through proxy nodes to reach other |
| unprotected IoT devices on a home network (e.g., Kimwolf DDoS botnet). |
| • Cyber Espionage Obfuscation: Allowing nation-state operators to blend in |
| with domestic consumer traffic while probing target networks. |
+-----------------------------------------------------------------------------------+
A secondary hazard of these proxy networks is local network exposure. As revealed by Synthient early in 2026, malicious actors frequently pivot through active proxy tunnels to breach other local devices behind a victim’s residential firewall. In one notable campaign, the operators of the Kimwolf DDoS botnet tunneled through commercial residential proxies directly into consumers’ local Wi-Fi networks, infecting secondary Android devices and enlisting them into high-volume distributed denial-of-service attacks.
Official Statements and Corporate Impact
The exposure of NetNut’s reliance on Popa forced its publicly traded corporate parent into a defensive crouch.
In a statement provided following the domain seizures, Omer Weiss, legal counsel for NetNut parent company Alarum Technologies, acknowledged the federal action while emphasizing corporate compliance:

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account."
Despite corporate assurances, the seizure banners plastered across NetNut and Alarum domains underscore the severity of the federal investigation. The inclusion of the IRS Criminal Investigation division alongside the FBI indicates that authorities are likely probing financial flows, potential wire fraud, tax compliance, and the monetization mechanisms tied to operating a covert, global botnet.
+-----------------------------------------------------------------------------------+
| CORPORATE & MARKET IMPACT SUMMARY |
+-----------------------------------------------------------------------------------+
| Entity: Alarum Technologies Ltd. [NASDAQ: ALAR] |
| Primary Brand Impacted: NetNut |
| Seized Asset Portfolio: NetNut.io, Alarum.io, Hundreds of C2 Domains |
| Law Enforcement Agencies: FBI (Federal Bureau of Investigation), |
| IRS-CI (Internal Revenue Service - CI) |
| Stock Price Trajectory: Pre-Takedown: ~$8.00+ ---> Post-Takedown: $2.62 |
| Overall Valuation Decline: Approximately 67% contraction |
+-----------------------------------------------------------------------------------+
Future Outlook & Consumer Defense
While the takedown of NetNut deals a massive blow to the illicit proxy market, experts warn that the underlying problem remains dynamic.
The Hydra Effect: Ecosystem Resilience and Reselling
The collapse of NetNut follows a similar enforcement action executed earlier in the year against IPIDEA, previously NetNut’s primary market competitor. As Benjamin Brundage, founder of Synthient, observed:
"NetNut gained significant popularity after the IPIDEA takedown. NetNut was on par with IPIDEA in terms of daily traffic, quality, size, and price per gigabyte. This takedown is going to have a big impact across the cybercrime community."
However, Google’s GTIG report cautions that residential proxy operators exhibit significant adaptability. When a proxy network’s primary botnet is dismantled, operators frequently convert their business models into third-party reselling—purchasing excess proxy capacity from competing operators or white-labeling remaining networks to maintain service contracts.
+-----------------------------------------------------------------------------------+
| THE RESIDENTIAL PROXY RECYCLING CYCLE |
+-----------------------------------------------------------------------------------+
| |
| [ Network Disruption / Takedown ] |
| | |
| v |
| [ Loss of Direct Exit Node Pool ] |
| | |
| v |
| [ Pivot to White-Labeling / Reselling Competitor Pools ] |
| | |
| v |
| [ Re-Infection of Consumers via New SDKs & App Ecosystems ] |
| |
+-----------------------------------------------------------------------------------+
Creating lasting disruption requires law enforcement and private industry to continuously target interconnected operators simultaneously, depriving cybercriminals of failover choices.
Defensive Guidance for Consumers and Enterprises
To protect home networks and enterprise environments from parasitic proxy networks:
For Consumers
- Stick to Certified Hardware: Avoid unbranded or extremely cheap Android-based TV streaming boxes sold through online marketplaces. Use devices certified by major manufacturers that run official, Play Protect-verified operating systems.
- Verify Play Protect Status: On Android TV devices, navigate to the system settings menu to confirm that the device holds Google Play Protect certification.
- Audit Smart TV App Installations: Limit app installations on Smart TV operating systems (such as LG webOS and Samsung Tizen) to well-known, verified streaming services. Remove unused utilities, third-party media players, or unverified background tools.
For Enterprise Defenders
- Monitor IP Reputation Anomalies: Inspect authentication logs for instances where a single account attempts logins from multiple residential IP ranges in short succession—a classic indicator of residential proxy-enabled password spraying.
- Implement Behavioral Telemetry: Use advanced bot mitigation solutions capable of analyzing TCP/IP fingerprint discrepancies, identifying connections where human residential IP signatures do not align with client device headers.
The takedown of NetNut and Popa serves as a stark reminder of how consumer internet-of-things devices are routinely weaponized for profit. As law enforcement turns its focus toward the commercial entities behind these operational backbones, the fight against parasitic proxy networks moves from basic software mitigations to structural, legal, and financial enforcement.
