FBI Seizes NetNut Residential Proxy Service and Popa Botnet Domains
- On July 2, 2026, the Federal Bureau of Investigation seized hundreds of domains tied to NetNut, a sprawling residential proxy service operated by publicly traded Israeli company Alarum...
- Federal law enforcement agencies replaced the NetNut homepage on July 2, 2026, with an official seizure banner notifying visitors that the domains had been taken down.
- Security research published by multiple firms on June 19, 2026, established that NetNut is a residential proxy network which populates the Popa botnet by distributing software to common...
On July 2, 2026, the Federal Bureau of Investigation seized hundreds of domains tied to NetNut, a sprawling residential proxy service operated by publicly traded Israeli company Alarum Technologies, according to official law enforcement notices and threat intelligence reports. The coordinated takedown involved industry partners and targeted the infrastructure behind the Popa botnet, a collection of at least two million consumer devices compromised by malicious software with little or no consent from victims.
FBI Domain Seizures Target NetNut and Popa Botnet Infrastructure
Federal law enforcement agencies replaced the NetNut homepage on July 2, 2026, with an official seizure banner notifying visitors that the domains had been taken down. According to the notice, the operation was executed in coordination with the Internal Revenue Service Criminal Investigation division alongside industry partners including Google, Lumen, and Shadowserver. The seized domains formed the backbone of the Popa botnet, which security experts state has long been synonymous with NetNut’s residential proxy infrastructure. According to Synthient proxy tracking service founder Benjamin Brundage, the domain seizures appear to have caused disruptions affecting both the Popa botnet and the NetNut proxy network built upon it.
Alarum Technologies acknowledged the enforcement action through legal counsel. Omer Weiss, legal counsel for NetNut parent Alarum Technologies, stated that the company was aware of the FBI seizure and cooperating with investigators. In a written statement, Weiss conveyed that Alarum treats the issue seriously and will cooperate entirely with law enforcement agencies to guarantee that any abuse of its systems undergoes a thorough investigation and that accountable parties face consequences. Following the law enforcement action, the corporate website for Alarum Technologies at alarum[.]io also displayed an FBI seizure notice, and the company’s stock fell roughly 67 percent over the past week to trade at $2.62 per share by July 8, 2026.
How Consumer Devices Became Unwitting Proxy Exit Nodes
Security research published by multiple firms on June 19, 2026, established that NetNut is a residential proxy network which populates the Popa botnet by distributing software to common household devices such as smart TVs and streaming boxes. This software converted residential hardware into always-on proxy nodes rented out to others. According to findings from the Google Threat Intelligence Group, these nodes were frequently utilized by cybercriminals and espionage groups to relay abusive and intrusive internet traffic, including mass content scraping, advertising fraud, and account takeover activity.
Google reported observing 316 distinct clusters of threat actors using suspected NetNut exit nodes during a single week in June 2026. The Google Threat Intelligence Group explained that malicious actors exploited these connections to mask their origin IP addresses when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks. In addition, researchers cautioned that turning a consumer appliance into an exit node allows unwanted data streams to traverse the hardware, giving cybercriminals potential entryways to other personal gadgets located inside the same household and ultimately leaving them vulnerable to digital dangers. In response, Google disabled accounts and services used by NetNut for malware command and control, shared technical intelligence regarding NetNut software development kits (SDKs) and backend infrastructure with law enforcement and other partners, and disabled apps known to bundle NetNut’s various SDKs.
Ecosystem Impact Following the IPIDEA Takedown
The disruption of NetNut follows legal actions earlier in the year that seized infrastructure for IPIDEA, identified as NetNut’s biggest competitor. Benjamin Brundage of Synthient noted that NetNut gained significant popularity following the IPIDEA takedown, operating on par with its rival in daily traffic, quality, size, and price per gigabyte. Brundage suggested that the takedown is going to have a big impact on the cybercrime community, which relies heavily on white-labeled and resold residential proxy networks to obscure illicit activities.
Despite the scope of the July 2 operation, security analysts caution that the residential proxy ecosystem remains fluid. Analysts at the Google Threat Intelligence Group cautioned that when proxy networks experience botnet impairment, operators frequently purchase bandwidth from rival services, essentially pivoting into resellers. While the FBI action has caused significant degradation to NetNut’s proxy network and business operations, reducing the available pool of devices for the proxy operator by millions, the GTIG report concludes that creating a lasting disruption means they must scale efforts to target the infrastructure of several interconnected providers.

