FBI Seizes Domains Linked to NetNut: A Crackdown on Cybercrime
The Federal Bureau of Investigation (FBI) made headlines today by announcing a significant joint operation with industry partners that resulted in the seizure of hundreds of domains related to NetNut, a large residential proxy service operated by the publicly traded Israeli company Alarum Technologies (NASDAQ: ALAR). This move follows a troubling investigation by KrebsOnSecurity, which detailed links between NetNut and the notorious Popa botnet, a malicious network comprising at least two million compromised devices.
The Popa Botnet: A Background
The Popa botnet is no small player in the cybercrime world. Comprised of devices often found in households—such as smart TVs and streaming boxes—the botnet relies on compromised software that turns these devices into always-on residential proxy nodes. Once activated, these nodes facilitate various illicit online activities, including mass content scraping, advertising fraud, and account takeovers. In a collaborative effort, three different security firms released findings on June 19 that publicly connected NetNut with this expansive botnet.
A Visible Response from Law Enforcement
In an unmistakable sign of the times, NetNut’s homepage was swiftly replaced with a seizure notice from the FBI, in collaboration with the Internal Revenue Service’s Criminal Investigation division. The notice expressed gratitude to major industry players like Google, Lumen, and Shadowserver for their assistance in dismantling the extensive network of domains tied to Popa, which has long been intertwined with NetNut’s infrastructure.
Insights from Google’s Threat Intelligence Group
Today, the Google Threat Intelligence Group (GTIG) published a blog post shedding light on NetNut’s proxy network. They pointed out that the network is frequently resold and white-labeled by various third-party providers, making it a valuable asset for cybercriminals aiming to conceal their malicious activities. In just one week in June 2026, GTIG observed 316 clusters of threat actors leveraging NetNut’s exit nodes, highlighting the pressing need to address such vulnerabilities.
“By using NetNut, malicious actors can obscure their original IP addresses while accessing their targets, performing password spray attacks, and breaching private networks,” the GTIG mentioned, emphasizing the risks involved when consumer devices transform into exit nodes.
Google’s Intervention
In response to this serious issue, Google acted decisively by disabling accounts and services associated with NetNut that were involved in malware command and control. The tech giant also shared crucial technical insights about NetNut’s software development kits (SDKs) with law enforcement agencies, platform providers, and cybersecurity researchers. This intervention aimed not just to mitigate immediate risks but also to strengthen the overall resilience of the cybersecurity ecosystem.
Alarum Technologies’ Response
Omer Weiss, representing Alarum Technologies, confirmed that the company was aware of the FBI’s seizure and is fully cooperating with ongoing investigations. “Alarum takes this matter seriously and will fully cooperate with law enforcement to ensure any misuse of its infrastructure is thoroughly investigated,” Weiss stated in a written response.
The Impact on the Cybercrime Landscape
The founder of the proxy tracking service Synthient, Benjamin Brundage, expressed that the domain seizures are likely to have a significant impact on the Popa botnet’s functionality and NetNut’s overall operation. As Brundage pointed out, the takedown could cripple a vital component of the cybercrime ecosystem, given that NetNut had gained traction following prior actions against its biggest competitor, IPIDEA.
Brundage noted, “NetNut has been incredibly popular among resellers, and its operational scale was comparable to IPIDEA, thus making it a critical asset for many involved in cybercrime.”
Implications for DDoS Attacks
Another potential benefit of the takedown is the reduction of large distributed denial-of-service (DDoS) attacks built on poorly secured residential proxy services. The Kimwolf botnet, for instance, utilized IPIDEA’s proxy connections to extend its reach by compromising devices within local networks. As Brundage explained, this disruption could lessen the vulnerabilities that have allowed such extensive DDoS operations to flourish.
Google’s Strategy Moving Forward
Google’s assessment concludes that current actions have significantly degraded NetNut’s service capabilities, effectively reducing the device pool available to the operators by millions. However, they also caution that disruption may not be permanent, as proxy networks can quickly reconstitute by sourcing proxies from willing resellers.
Recognizing the Risks of Residential Proxy Networks
Unfortunately, many smart TVs and other internet-enabled devices have become unwitting participants in this shadowy world of residential proxies. Several apps available on platforms like Samsung and LG smart TVs either come pre-installed or prompt installation of SDKs designed to convert these devices into residential proxy nodes.
Research from Spur highlights alarming trends: approximately 42% of apps on LG’s webOS exploit this vulnerability, while over a quarter of Samsung’s Tizen apps fall under similar scrutiny.
Best Practices for Users
Google advises consumers to be diligent. When purchasing streaming devices, stick to reputable brands and avoid dubious apps that may compromise security. There’s also the emphasis on ensuring an Android device bears the official Android TV OS and Play Protect certification to mitigate the risk of being inadvertently enrolled in these malicious residential proxy services.
Continuing Trends and Developments
Updates following the seizure indicate that Alarum Technologies’ web presence has also been tainted by legal ramifications, leading to a stark decline in their stock value following the FBI action. As of now, their share price has plummeted approximately 67% within a week, showing tangible economic effects tied to these legal developments.
In this ever-evolving landscape of cybersecurity, vigilance remains paramount, as both consumers and manufacturers must adapt to uphold security against the backdrop of increasing digital threats. The latest actions serve as a reminder of the constant battle between cybercriminal activities and the response measures taken by law enforcement and tech companies alike.