FBI Dismantles "Popa" Botnet: The Fall of NetNut and the War on Residential Proxy Networks

In a significant blow to the cybercrime underground, the Federal Bureau of Investigation (FBI), in coordination with the Internal Revenue Service (IRS) Criminal Investigation division and a coalition of global technology partners, has executed a massive operation to dismantle the infrastructure of NetNut. The residential proxy service, operated by the publicly-traded Israeli firm Alarum Technologies [NASDAQ: ALAR], had long been identified by security researchers as the backbone of the "Popa" botnet—a vast, illicit network comprised of at least two million compromised consumer devices.

The takedown, which involved the seizure of hundreds of domains, marks a pivotal moment in the ongoing battle against the weaponization of the "Internet of Things" (IoT). By transforming everyday home appliances—such as smart TVs, streaming boxes, and home routers—into "exit nodes" for malicious traffic, NetNut and its underlying Popa botnet provided cybercriminals with a sophisticated, highly anonymous method to launch advertising fraud, conduct account takeovers, and scrape sensitive data from corporate environments.

The Chronology of a Collapse

The operation, finalized this week, serves as the culmination of months of intense scrutiny by the cybersecurity community. The pressure on Alarum Technologies intensified dramatically in late June 2026, when three independent security firms released concurrent reports exposing the symbiotic relationship between the company’s commercial proxy services and the malicious Popa botnet.

The Investigative Trail

  • June 19, 2026: Security researchers publish evidence linking NetNut’s residential proxy network to the distribution of malicious software (SDKs) targeting home-based devices.
  • Late June 2026: Google’s Threat Intelligence Group (GTIG) begins active monitoring, observing hundreds of distinct threat actor clusters utilizing NetNut nodes for espionage and credential-stuffing attacks.
  • Early July 2026: The FBI and IRS officially intervene, seizing the primary domains associated with NetNut. The familiar, stark seizure banner replaces the company’s homepage.
  • July 8, 2026: The scope of the seizure expands to include the parent company’s corporate portal, alarum.io. NASDAQ trading data confirms a massive market collapse for Alarum Technologies, with shares plummeting approximately 67% to $2.62.

Anatomy of the Popa Botnet

The Popa botnet was not built through traditional "phishing" or complex malware campaigns; rather, it relied on the exploitation of consumer trust and the ubiquity of unverified third-party software. The botnet’s engine was primarily driven by Software Development Kits (SDKs) embedded within applications for streaming media boxes and smart TVs.

When a user installed an app—often designed to facilitate the streaming of pirated content—they were unknowingly granting the device the status of a residential proxy node. Once active, the device remained in an "always-on" state, routing traffic for unknown third parties. Because the traffic originated from a legitimate residential IP address, it bypassed traditional security filters designed to block traffic from known data centers or suspicious VPNs.

Google’s investigation revealed the scale of this abuse: in a single week in June 2026, threat actors used these nodes to mask their locations while conducting password spray attacks and accessing internal corporate networks. Furthermore, the presence of this software created an internal security risk for the homeowners themselves; by allowing external, unvetted traffic to traverse the home network, the compromised devices effectively exposed all other private devices behind the same firewall to potential infiltration.

FBI Seizes NetNut Proxy Platform, Popa Botnet

Official Responses and Corporate Accountability

As the digital infrastructure was seized, the legal and corporate ramifications began to unfold. Alarum Technologies, through its legal counsel Omer Weiss, initially issued a statement acknowledging the investigation.

"Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss stated.

However, the rapid expansion of the FBI’s seizure to the corporate domain of Alarum suggests that investigators are looking beyond the service’s "users" and examining the internal operations of the parent company itself.

The Role of Technology Partners

The success of this operation was contingent upon a massive inter-industry effort. Companies including Google, Lumen, and the Shadowserver Foundation provided critical telemetry that allowed law enforcement to map the command-and-control (C2) infrastructure of the Popa botnet. Google, in particular, took proactive steps to disable compromised accounts and remove applications from their ecosystem that bundled the malicious NetNut SDKs, effectively cutting off the "oxygen" the botnet needed to reach new victims.

The Broader Implications for the Proxy Ecosystem

The dismantling of NetNut is the second major blow to the residential proxy market in less than a year. Following the earlier seizure of IPIDEA, another major player in the space, industry observers suggest that the residential proxy market is in a state of chaotic transition.

Benjamin Brundage, founder of the proxy tracking service Synthient, notes that the collapse of NetNut will have a profound, albeit potentially temporary, impact on the cybercrime community. "NetNut was a massive aggregator," Brundage explained. "After IPIDEA was taken down, NetNut absorbed a significant portion of that traffic. Their quality, size, and price-per-gigabyte made them the go-to for resellers. Removing them removes one of the most reliable tools in the cybercriminal’s arsenal."

FBI Seizes NetNut Proxy Platform, Popa Botnet

The "Reseller" Problem

However, industry experts remain cautious about the long-term effectiveness of these seizures. The "residential proxy" model is inherently fluid. When a large provider is shuttered, the underlying infrastructure often fragments, with operators turning into "resellers" of smaller, less visible networks to obfuscate their tracks. Google’s intelligence reports warn that the ecosystem is resilient; as one network falls, operators simply pivot to buying capacity from remaining competitors, effectively turning a "network operator" into a "proxy broker."

A Warning for Consumers: The Hidden Risks in Your Living Room

The NetNut case highlights a troubling trend: the commodification of the consumer home network. The research provided by companies like Spur.us paints a alarming picture. According to their findings, nearly 42 percent of apps available on LG’s webOS and over 25 percent of apps for Samsung’s Tizen operating system contain residential proxy SDKs.

This is not limited to "shady" streaming boxes purchased from overseas marketplaces. While those devices are the most common vectors—often arriving pre-loaded with malicious software or requiring custom, insecure Android builds—the risk extends to mainstream devices if users are not careful about the apps they install.

Guidance for Protecting Your Home Network

To mitigate the risks identified in the wake of the NetNut/Popa investigation, cybersecurity professionals offer the following recommendations:

  1. Stick to Official Ecosystems: Avoid "jailbroken" streaming devices or those that require the manual installation of unofficial operating systems. Only use devices that feature official Google Play Protect certification or manufacturer-vetted app stores.
  2. Exercise App Judiciousness: Just because an app is available on a smart TV store does not mean it is benign. Research developers before installing, and uninstall any apps that are no longer in use.
  3. Network Segmentation: For advanced users, isolating IoT devices on a "guest" or separate VLAN (Virtual Local Area Network) can prevent a compromised smart TV from accessing sensitive devices, such as personal computers or network-attached storage, on the same home network.
  4. Monitor Traffic: Be wary of devices that show high levels of background data usage when they are not actively being used for streaming.

Conclusion

The FBI-led action against NetNut is a clear signal to proxy providers that they can no longer hide behind the veil of "legitimate business services" when their infrastructure is primarily fueling malicious botnets. While the immediate disruption is significant, the persistence of the residential proxy model suggests that this will remain a long-term cat-and-mouse game.

For the average consumer, the lesson is clear: the convenience of "free" or "unlocked" streaming content often comes with a hidden, high-stakes price tag—the security of their home network. As the digital landscape continues to evolve, the distinction between a harmless household gadget and a weaponized cyber-asset has never been thinner.