# FBI Takes Down NetNut Proxy Network, Disrupting 2+ Million-Device Botnet Used in Cybercrime Operations
The Federal Bureau of Investigation and the Internal Revenue Service Criminal Investigation division have seized hundreds of domains associated with NetNut, the residential proxy service operated by publicly-traded Israeli company Alarum Technologies (NASDAQ: ALAR). The coordinated takedown dismantles critical infrastructure used by threat actors to mask malicious activity, following weeks of public reporting that linked the proxy network to the Popa botnet—a sprawling collection of at least two million compromised devices installed on consumer electronics with little or no user consent.
## The Threat
NetNut's Role in the Criminal Ecosystem
NetNut operated as a legitimate-facing but fundamentally compromised infrastructure platform. The service distributed software to consumer devices—primarily smart TVs and streaming boxes—that transformed them into always-on residential proxy nodes. Once infected, these devices became part of the Popa botnet, allowing cybercriminals to rent exit nodes from NetNut and its resellers.
The implications for individual users are severe:
According to Google's Threat Intelligence Group (GTIG), the scale of abuse was staggering. In a single week during June 2026, Google identified 316 distinct clusters of threat actors using suspected NetNut exit nodes, including both cybercriminal and state-sponsored espionage groups.
## Background and Context
The Chain of Discovery
Security researchers first raised public alarms on June 19, 2026, when three independent security firms published coordinated findings connecting NetNut to the Popa botnet. The research directly contradicted Alarum Technologies' public positioning of NetNut as a legitimate proxy service, and the company responded defensively, threatening legal action against journalists and researchers reporting on the connection.
By late June, KrebsOnSecurity published additional investigative reporting on the botnet's connection to NetNut, providing the specific technical evidence that would eventually inform law enforcement action.
Timing and Competitive Dynamics
The NetNut takedown follows law enforcement action against IPIDEA, NetNut's primary competitor in the residential proxy market, earlier in 2026. According to Benjamin Brundage, founder of proxy tracking service Synthient, NetNut actually benefited from IPIDEA's demise, gaining "significant popularity after the IPIDEA takedown." The NetNut seizure therefore represents law enforcement's second major strike against the residential proxy ecosystem—a critical component of modern cybercrime infrastructure.
The operational timing is significant: with IPIDEA offline and NetNut now seized, criminal actors face a severe shortage of trusted, large-scale proxy infrastructure, potentially fragmenting attack campaigns and forcing threat groups to seek alternative evasion methods.
## Technical Details
How NetNut Compromised Devices
NetNut's software development kits (SDKs) were embedded in legitimate-appearing applications available on various platforms. The software was particularly prevalent on streaming and smart TV applications, where users were unlikely to scrutinize permissions or network behavior. Once installed, the malware:
1. Operated silently in the background with minimal visibility to end users
2. Redirected traffic through residential IP addresses, making it appear to originate from legitimate home networks
3. Created persistent nodes that remained active 24/7, providing continuous proxy capacity
4. Resold capacity through NetNut's platform and white-labeled proxy providers to criminal customers
| Attack Vector | Usage |
|---|---|
| Content Scraping | Mass harvesting of proprietary data and intellectual property |
| Ad Fraud | Manipulating ad impressions and click metrics for financial gain |
| Account Takeovers | Distributed password spray attacks appearing to originate from residential networks |
| Credential Abuse | Testing stolen username/password combinations across services |
| Espionage | Obfuscating access to victim networks for nation-state actors |
Law Enforcement and Industry Response
The seizure notice, published on NetNut's homepage today, was signed by the FBI, IRS Criminal Investigation, and thanked industry partners including Google, Lumen Technologies, Shadowserver Foundation, and others for technical assistance. Google's role was particularly significant:
## Implications for Organizations and Individuals
Immediate Security Concerns
Organizations should assess their exposure in several ways:
1. Endpoint audits: Review connected devices (smart TVs, streaming boxes, IoT devices) for unknown applications that may contain NetNut SDKs
2. Network monitoring: Look for outbound traffic patterns consistent with proxy services or bot traffic
3. Account security: Monitor for unauthorized access attempts, particularly distributed password spray attacks that may have used NetNut infrastructure
Broader Implications
The NetNut takedown reveals several uncomfortable truths about consumer device security:
## Recommendations
For Consumers
For Organizations
For ISPs and Platform Providers
---
## HackWire Analysis
The NetNut takedown is significant not just as an isolated law enforcement victory, but as evidence of a deliberate, coordinated squeeze on proxy infrastructure that cybercriminals depend on. The sequential takedowns of IPIDEA and now NetNut—the two largest residential proxy networks—suggest law enforcement has mapped the supply chain and is systematically dismantling each node. This is exactly the right strategy: individual takedowns are easily replaced, but eliminating the top two platforms creates a genuine scarcity that defensive teams can exploit.
What makes this especially noteworthy is the speed: researchers published evidence on June 19, and law enforcement acted within weeks. Compare this to the typical 12-18 month lag between discovery and court action in other infrastructure takedowns. The coordination between Google, Lumen, Shadowserver, and FBI suggests a playbook that's being perfected and could accelerate future actions.
However, defenders should not assume this problem is solved. NetNut's demise will push criminal actors toward either: (1) smaller, distributed proxy networks that are harder to identify and seize, or (2) direct exploitation of compromised edge routers and corporate VPNs as proxy infrastructure. The second option is particularly dangerous because it means future proxy traffic won't originate from consumer devices but from legitimate business networks, making it exponentially harder for defenders to distinguish attack traffic from normal business activity.
Organizations should treat this window—the period of proxy infrastructure scarcity—as an opportunity to strengthen detection of proxy-based attacks before adversaries adapt. The takedown is a speed bump, not a solution. — *HackWire Editorial*
---
## Related Coverage