The FBI seized hundreds of domains tied to NetNut, a residential proxy service operated by publicly traded Israeli firm Alarum Technologies, in a coordinated action that also dismantled the Popa botnet — a network of at least two million compromised devices.
The seizure notice, co-signed by the Internal Revenue Service Criminal Investigation division, appeared on NetNut’s homepage Thursday. Google Threat Intelligence Group, Lumen Technologies, and the Shadowserver Foundation assisted in the operation, which targeted infrastructure used to relay malicious traffic including account takeover attempts, content scraping, and advertising fraud.
NetNut’s residential proxy service populated the Popa botnet by embedding software development kits into smart TV and streaming box applications. Google found that 42 percent of LG webOS apps and over a quarter of Samsung Tizen apps contained SDKs that turned devices into always-on proxy nodes, often without meaningful user consent.
In a single week in June 2026, Google observed 316 distinct threat actor clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. The FBI action follows KrebsOnSecurity’s June reporting that connected NetNut directly to the Popa botnet infrastructure.
Alarum Technologies legal counsel Omer Weiss confirmed the company is aware of the seizure and cooperating with investigators.
