The Federal Bureau of Investigation seized hundreds of domains connected to NetNut, a residential proxy service operated by Alarum Technologies. The NetNut homepage was replaced with a seizure banner from the FBI and the Internal Revenue Service Criminal Investigation division.

Alarum Technologies is a publicly-traded Israeli company listed on NASDAQ under the ticker ALAR. The FBI worked with industry partners, including Google, Lumen, and Shadowserver, to complete the domain seizures. This action occurred approximately two weeks after security firms published findings linking NetNut to the Popa botnet.

The Popa botnet comprises at least two million devices compromised by malicious software. On June 19, three security firms released findings indicating that NetNut populates the Popa botnet. NetNut distributes software for devices such as smart TVs and streaming boxes, turning these systems into always-on residential proxy nodes that are then rented to others.

The Google Threat Intelligence Group posted a blog entry stating that NetNut's proxy network is widely resold and white-labeled by third-party proxy providers. "These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks," the group said. "Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats." During one week in June 2026, the group observed 316 distinct clusters of threat actors using suspected NetNut exit nodes.

Omer Weiss, legal counsel for Alarum Technologies, said the company was aware of the FBI's seizure and is cooperating with investigators. "Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated and those responsible are held to account," Weiss said.

Benjamin Brundage, founder of the proxy tracking service Synthient, stated that the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network. "Also NetNut has been incredibly common among resellers, and they were on par with IPIDEA in terms of their daily traffic, quality, size, price per gigabyte, all of it," Brundage said.

Google disabled accounts and services used by NetNut for malware command and control. Google also disabled apps known to bundle NetNut's various software development kits (SDKs). Google stated these actions caused degradation to NetNut's proxy network and business operations, reducing the available pool of devices for the proxy operator by millions.

Spur, another security firm, reported findings on proxy components. Spur found that 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn the television into an always-on residential proxy node. Additionally, Spur found that more than a quarter of apps made for Samsung's Tizen operating system contained residential proxy components.