The FBI Seized NetNut — The Residential Proxy Behind 2 Million Hijacked Devices
This week, the FBI, working alongside Google's Threat Intelligence Group, Lumen, Shadowserver, and the IRS Criminal Investigation division, seized hundreds of domains belonging to NetNut, the sprawling residential proxy network operated by Alarum Technologies — a publicly traded Israeli company listed on the NASDAQ. NetNut was the operator behind Popa, a botnet of at least two million consumer devices, mostly cheap Android streaming boxes you can pick up on any e-commerce site for less than $30, that quietly turn your TV into an always-on residential proxy node. The seizure banner now sits on NetNut's homepage, thanking its industry partners for the dismantling effort that Google first flagged back in January 2026 with the IPIDEA takedown.
Here's what most proxy providers would rather you not think about: while they market their networks as "AI data infrastructure," the actual traffic tells a different story. Google's Threat Intelligence Group found 316 distinct clusters of threat actors using suspected NetNut exit nodes in a single week of June 2026 — espionage groups, credential stuffers, ad-fraud operators all routing through your living room. Synthient's research, published earlier this month, showed the majority of residential proxy traffic targets financial institutions and e-commerce platforms, not machine learning pipelines. The devices don't just relay traffic; they also open tunnels into the local network, meaning bad actors can reach your smart TV, your phone, maybe even your PC if you leave ports open. When a consumer device becomes an exit node, unauthorized network traffic passes through it, and bad actors can access other private devices on the same home network — which is exactly how Popa turned $30 streaming boxes into a persistent communications layer for cybercrime.

What makes this particularly interesting from an operational perspective is that Alarum Technologies went public with all of this running, and the market apparently didn't care much — the NASDAQ listing suggests investors were happy to treat a botnet-driven proxy service as a legitimate business. The Popa/NetNut story follows Google's January 2026 disruption of IPIDEA, another residential proxy network, suggesting this is becoming a recurring pattern. Residential proxies are everywhere in modern threat operations, but they're also everywhere in home networking, quietly sitting behind your router, forwarding your IP address to half the internet. NetNut's services are heavily resold and white-labeled by third-party providers, which means even after the FBI

Sources
Comments
Post a Comment