FBI, Google disrupt NetNut proxy network co-opting 2 million devices

This digest was compiled by AI from multiple sources — links to the originals are below.
The FBI and Google disrupted NetNut, a residential proxy network that co-opted more than two million consumer devices, and seized hundreds of domains in a coordinated international operation. The network allowed malicious traffic to route through legitimate domestic IP addresses, bypassing standard security filters.
Key Facts
- At least 316 distinct threat clusters used NetNut exit nodes in a single week in June 2026 for password spraying, credential stuffing, advertising fraud and sensitive data scraping.
- The joint operation included Lumen Technologies, the Shadowserver Foundation, and the US Internal Revenue Service Criminal Investigation division.
- Security firms Qurium and Synthient established direct links between Alarum Technologies' executive leadership and the original developers of the malicious Popa SDK.
- Alarum Technologies stated it will fully cooperate with law enforcement.
The Takedown Operation
The FBI and Google's Threat Intelligence Group coordinated the operation with Lumen Technologies, the Shadowserver Foundation, and the US Internal Revenue Service Criminal Investigation division. The joint effort targeted the digital infrastructure behind the NetNut residential proxy service. Investigators seized hundreds of domains associated with the proxy network.
The Device Co-Optation
Security researchers track the NetNut network as the 'Popa' botnet, an engineered stealth communications layer. The botnet embedded deceptive software development kits in inexpensive, off-brand Android-based smart TVs, streaming media boxes and unofficial apps such as SmartTube. The network co-opted more than two million consumer devices, turning home internet connections into residential proxy exit nodes. This allowed malicious traffic to route through legitimate domestic IP addresses, bypassing standard data centre blocks and security filters.
The Alarum Technologies Link
Independent cybersecurity journalist Brian Krebs reported that NetNut could be linked to Alarum Technologies Ltd, a publicly traded Israeli firm listed on NASDAQ. Security firms Qurium and Synthient established direct links between Alarum's executive leadership and the original developers of the malicious Popa SDK. Alarum said it takes the matter seriously and will fully cooperate with law enforcement. Google researchers found at least 316 distinct threat clusters used NetNut exit nodes in a single week in June 2026 and assessed with high confidence that many popular residential proxy brands whitelabel the NetNut botnet.