The FBI, in coordination with Google’s Threat Intelligence Group (GTIG), Lumen Technologies, The Shadowserver Foundation, and other industry partners, has seized hundreds of domains associated with NetNut — a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies. The operation, announced on 3 July 2026, dismantled the infrastructure behind the Popa botnet, which had silently recruited at least 2 million consumer devices into a for-hire proxy network.
What NetNut Actually Was
NetNut marketed itself as a legitimate residential proxy service — a business that sells traffic routing through real consumer IP addresses, used by enterprises for ad verification, price scraping, and competitive intelligence. The problem: much of that consumer bandwidth was not volunteered. NetNut populated its network by embedding SDKs into software distributed to smart TVs and streaming boxes, often without meaningful disclosure to device owners.
The resulting Popa botnet gave subscribers access to residential exit nodes distributed globally — making malicious traffic indistinguishable from ordinary home browsing at the network level.
Who Was Using It
The scale of criminal and state abuse became clear when GTIG released its findings: in a single week during June 2026, analysts observed 316 distinct threat actor clusters routing activity through suspected NetNut exit nodes. The clusters spanned both financially-motivated cybercriminals and nation-state espionage groups.
Operational uses included:
- Credential stuffing and password spray attacks — residential IPs defeat most account lockout and IP reputation controls
- Command-and-control obfuscation — malware operators routing C2 traffic through residential nodes to evade detection
- Ransomware reconnaissance and access broker activity — scouting target environments via IP addresses that don’t trigger threat intelligence blocklists
- Espionage operations — state-linked groups using residential exit nodes to conceal attribution during long-term access operations against government and critical infrastructure targets
The breadth of users underscores a structural problem: residential proxy networks create shared infrastructure that serves both grey-market commercial clients and adversaries simultaneously. Defenders blocking NetNut exit IPs would have been blocking legitimate residential addresses globally.
The Takedown
The FBI seized domains central to NetNut’s infrastructure. Google estimates the action has caused “significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions.” However, Google notes with high confidence that many popular residential proxy brands were whitelabeling NetNut — meaning affiliated proxy services operating under different brand names may continue until their own infrastructure is addressed.
Alarum Technologies, the NASDAQ-listed parent company of NetNut, had not issued a formal public statement at time of publication.
Defender Implications
For network defenders, the primary concern is not NetNut itself post-takedown but the pattern it represents. Residential proxy networks are now a standard component of sophisticated attack infrastructure. IP reputation-based defences provide limited protection when adversaries route through legitimate household addresses.
Key recommendations from GTIG and industry partners:
- Threat intelligence feeds should include residential proxy exit node ranges, not just traditional datacenter IPs. Several threat intelligence providers now maintain residential proxy blocklists
- Behavioural detection over IP reputation — look for authentication anomalies, unusual access patterns, and session characteristics rather than relying solely on IP blocklisting
- Device management for IoT and smart TV infrastructure — organisations with managed device fleets should audit third-party SDK permissions and review whether consumer devices on corporate networks could be enrolled in proxy schemes
For organisations that previously saw NetNut-associated traffic, GTIG has advised reviewing logs for the June window to identify any threat cluster activity that may have been masked by residential IP obfuscation.