IC Technology & Cyber — 2026-07-03

FBI Seizes NetNut Proxy Platform and Dismantles Popa Botnet Infrastructure

BLUFSeizing NetNut's domain and command infrastructure imposes migration costs on hundreds of threat clusters but leaves two million compromised devices available for reconstitution by successor networks.

The FBI, working with the Internal Revenue Service Criminal Investigation division, Google, Lumen, Shadowserver and other industry partners, seized hundreds of domains tied to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies, and the underlying Popa botnet 1. Google's Threat Intelligence Group said it disabled Google accounts and services NetNut used for malware command and control, shared technical intelligence on NetNut's SDKs and backend infrastructure with platform providers and law enforcement, and had Play Protect disable apps bundling NetNut code 2. GTIG estimated the network at a minimum of 2 million devices worldwide, populated largely through smart TVs and streaming boxes, and said it observed 316 distinct threat clusters, including cybercriminal and espionage groups, using suspected NetNut exit nodes in a single week in June 23. Alarum Technologies' legal counsel Omer Weiss said the company is aware of the seizure and cooperating with investigators 1; the action follows Google's January disruption of competing proxy network IPIDEA 24.

Analysis
The takedown strips NetNut's domain infrastructure and Google-hosted command-and-control channels but leaves roughly two million compromised smart TVs and streaming boxes physically intact, since remediation depends on individual owners rather than the seizure itself. Google's January disruption of the rival IPIDEA network set the template: displaced customers migrated to whitelabel resellers instead of losing proxy access, and the same adaptation is expected here. That 316 distinct threat clusters, spanning espionage and cybercriminal operators, drew on NetNut's exit nodes in a single week shows the network served as core tradecraft infrastructure rather than mere ad fraud, so those operators absorb a migration cost more than a lasting capability loss. Sourcing rests on Google's primary disclosure and prior independent Krebs reporting, with SiliconANGLE and The Hacker News largely restating rather than adding; Alarum's continued cooperation as a public company leaves open a reading of this as domain-level disruption rather than structural dismantlement of a proxy-reselling model that is not inherently illegal.
4 sources
  1. FBI Seizes NetNut Proxy Platform, Popa Botnet - Krebs on Security
  2. Google's Continued Disruption of Malicious Residential Proxy Networks - Google Cloud Blog
  3. Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices - The Hacker News
  4. Google disrupts NetNut residential proxy network built on 2 million devices - SiliconANGLE

View in full brief →

UNCLASSIFIED // OPEN SOURCE