# FBI Takes Down NetNut Proxy Network, Disrupting 2+ Million-Device Botnet Used in Cybercrime Operations


The Federal Bureau of Investigation and the Internal Revenue Service Criminal Investigation division have seized hundreds of domains associated with NetNut, the residential proxy service operated by publicly-traded Israeli company Alarum Technologies (NASDAQ: ALAR). The coordinated takedown dismantles critical infrastructure used by threat actors to mask malicious activity, following weeks of public reporting that linked the proxy network to the Popa botnet—a sprawling collection of at least two million compromised devices installed on consumer electronics with little or no user consent.


## The Threat


NetNut's Role in the Criminal Ecosystem


NetNut operated as a legitimate-facing but fundamentally compromised infrastructure platform. The service distributed software to consumer devices—primarily smart TVs and streaming boxes—that transformed them into always-on residential proxy nodes. Once infected, these devices became part of the Popa botnet, allowing cybercriminals to rent exit nodes from NetNut and its resellers.


The implications for individual users are severe:


  • Device misuse: Consumer electronics became unwitting participants in global cybercrime operations
  • Network exposure: Unauthorized traffic routed through home networks exposed other connected devices to direct threats
  • Performance degradation: Infected devices consumed bandwidth for criminal purposes while homeowners footed the bandwidth bill
  • Legal liability: Home networks became conduits for illegal activity without owners' knowledge

  • According to Google's Threat Intelligence Group (GTIG), the scale of abuse was staggering. In a single week during June 2026, Google identified 316 distinct clusters of threat actors using suspected NetNut exit nodes, including both cybercriminal and state-sponsored espionage groups.


    ## Background and Context


    The Chain of Discovery


    Security researchers first raised public alarms on June 19, 2026, when three independent security firms published coordinated findings connecting NetNut to the Popa botnet. The research directly contradicted Alarum Technologies' public positioning of NetNut as a legitimate proxy service, and the company responded defensively, threatening legal action against journalists and researchers reporting on the connection.


    By late June, KrebsOnSecurity published additional investigative reporting on the botnet's connection to NetNut, providing the specific technical evidence that would eventually inform law enforcement action.


    Timing and Competitive Dynamics


    The NetNut takedown follows law enforcement action against IPIDEA, NetNut's primary competitor in the residential proxy market, earlier in 2026. According to Benjamin Brundage, founder of proxy tracking service Synthient, NetNut actually benefited from IPIDEA's demise, gaining "significant popularity after the IPIDEA takedown." The NetNut seizure therefore represents law enforcement's second major strike against the residential proxy ecosystem—a critical component of modern cybercrime infrastructure.


    The operational timing is significant: with IPIDEA offline and NetNut now seized, criminal actors face a severe shortage of trusted, large-scale proxy infrastructure, potentially fragmenting attack campaigns and forcing threat groups to seek alternative evasion methods.


    ## Technical Details


    How NetNut Compromised Devices


    NetNut's software development kits (SDKs) were embedded in legitimate-appearing applications available on various platforms. The software was particularly prevalent on streaming and smart TV applications, where users were unlikely to scrutinize permissions or network behavior. Once installed, the malware:


    1. Operated silently in the background with minimal visibility to end users

    2. Redirected traffic through residential IP addresses, making it appear to originate from legitimate home networks

    3. Created persistent nodes that remained active 24/7, providing continuous proxy capacity

    4. Resold capacity through NetNut's platform and white-labeled proxy providers to criminal customers


    | Attack Vector | Usage |

    |---|---|

    | Content Scraping | Mass harvesting of proprietary data and intellectual property |

    | Ad Fraud | Manipulating ad impressions and click metrics for financial gain |

    | Account Takeovers | Distributed password spray attacks appearing to originate from residential networks |

    | Credential Abuse | Testing stolen username/password combinations across services |

    | Espionage | Obfuscating access to victim networks for nation-state actors |


    Law Enforcement and Industry Response


    The seizure notice, published on NetNut's homepage today, was signed by the FBI, IRS Criminal Investigation, and thanked industry partners including Google, Lumen Technologies, Shadowserver Foundation, and others for technical assistance. Google's role was particularly significant:


  • Account disablement: Google disabled all Google accounts and services used by NetNut for malware command and control
  • SDK analysis: Google analyzed NetNut SDKs and shared technical intelligence with platform providers, law enforcement, and researchers
  • Application removal: Google removed applications known to bundle NetNut SDKs from its platforms
  • Infrastructure sharing: Google provided signals to other platforms enabling them to identify and remove compromised applications

  • ## Implications for Organizations and Individuals


    Immediate Security Concerns


    Organizations should assess their exposure in several ways:


    1. Endpoint audits: Review connected devices (smart TVs, streaming boxes, IoT devices) for unknown applications that may contain NetNut SDKs

    2. Network monitoring: Look for outbound traffic patterns consistent with proxy services or bot traffic

    3. Account security: Monitor for unauthorized access attempts, particularly distributed password spray attacks that may have used NetNut infrastructure


    Broader Implications


    The NetNut takedown reveals several uncomfortable truths about consumer device security:


  • Manufacturers prioritize features over security: Smart TV and streaming device manufacturers often bundle third-party SDKs with minimal scrutiny
  • Legitimate applications as vectors: Criminal infrastructure is hidden within seemingly legitimate apps available through official channels
  • Scale of compromise: At least two million devices were compromised in this single botnet—one of many active in the threat landscape
  • Supply chain vulnerability: White-labeled proxy services mean criminal actors can reach the same infrastructure through multiple resellers, making disruption difficult

  • ## Recommendations


    For Consumers


  • Review device applications: Audit smart TV and streaming device apps, removing anything unfamiliar or from untrusted developers
  • Monitor network: Check your router's bandwidth usage for unexplained spikes
  • Update regularly: Keep firmware and applications current to patch known vulnerabilities

  • For Organizations


  • Network segmentation: Isolate IoT and consumer devices from critical business networks
  • Proxy monitoring: Implement tools to detect outbound proxy traffic from unexpected sources
  • Threat intelligence integration: Subscribe to feeds tracking proxy infrastructure takedowns and new threat actors replacing seized services
  • Incident response preparation: Develop playbooks for responding to evidence that your network has been used in credential abuse or data scraping campaigns

  • For ISPs and Platform Providers


  • Automated detection: Develop signatures to identify proxy traffic and botnet communications at network edges
  • SDK audits: Require application developers to disclose third-party SDKs and their permissions
  • Rapid takedown: Establish processes to quickly disable accounts and services identified as botnet infrastructure

  • ---


    ## HackWire Analysis


    The NetNut takedown is significant not just as an isolated law enforcement victory, but as evidence of a deliberate, coordinated squeeze on proxy infrastructure that cybercriminals depend on. The sequential takedowns of IPIDEA and now NetNut—the two largest residential proxy networks—suggest law enforcement has mapped the supply chain and is systematically dismantling each node. This is exactly the right strategy: individual takedowns are easily replaced, but eliminating the top two platforms creates a genuine scarcity that defensive teams can exploit.


    What makes this especially noteworthy is the speed: researchers published evidence on June 19, and law enforcement acted within weeks. Compare this to the typical 12-18 month lag between discovery and court action in other infrastructure takedowns. The coordination between Google, Lumen, Shadowserver, and FBI suggests a playbook that's being perfected and could accelerate future actions.


    However, defenders should not assume this problem is solved. NetNut's demise will push criminal actors toward either: (1) smaller, distributed proxy networks that are harder to identify and seize, or (2) direct exploitation of compromised edge routers and corporate VPNs as proxy infrastructure. The second option is particularly dangerous because it means future proxy traffic won't originate from consumer devices but from legitimate business networks, making it exponentially harder for defenders to distinguish attack traffic from normal business activity.


    Organizations should treat this window—the period of proxy infrastructure scarcity—as an opportunity to strengthen detection of proxy-based attacks before adversaries adapt. The takedown is a speed bump, not a solution. — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)