Comparison

The NetNut Botnet Takedown: How the FBI Took Down 2 Million Hijacked Devices

The NetNut botnet takedown explained: how the FBI seized NetNut after Krebs tied it to Popa, a 2M-device proxy botnet, and why proxy sourcing decides all.

HProxy Team · ·14 min read
HProxy. Comparison

Free proxies won't hold up here.

Shared datacenter IPs get flagged and dropped fast. When it has to hold, gaming, streaming, accounts, you need mobile and residential IPs that read as a real device, from $0.65/GB, pay as you go.

See plans & pricing

The NetNut takedown became public on July 2, 2026, when the FBI and IRS Criminal Investigation seized hundreds of NetNut domains (netnut.com and netnut.io among them) in a coordinated action with Google. The seizure followed reporting by KrebsOnSecurity, which in June tied the NetNut residential proxy service to a botnet that researchers track as "Popa," allegedly built from more than 2 million hijacked smart TVs and streaming boxes and quietly rented out as residential proxy exit nodes. NetNut's parent company disputes that characterization. Either way, the case is the clearest example yet of why the only proxy spec that actually matters is where the IPs come from.

We run a proxy network, so this one is close to home. A residential proxy is only ever as clean as the way its IPs were sourced, and the NetNut case is what happens when nobody asks that question hard enough. Here is what is confirmed, what is still alleged, who owns what, and how to make sure the pool you are paying for is not a botnet with a billing page.

What the FBI actually seized

On July 2, 2026, the FBI and IRS Criminal Investigation (IRS-CI) seized hundreds of domains belonging to NetNut, including its main sites netnut.com and netnut.io, and replaced them with a government seizure notice. The Justice Department publicly confirmed the seizure later that week. NetNut was one of the larger names in the residential proxy market, the kind of provider that sells access to millions of "real" home IP addresses for scraping, ad verification, and similar work. This was not a fly-by-night operation: its parent reported $11.7 million in revenue in the first quarter of 2026, up 64% from a year earlier.

The action was coordinated. Google's Threat Intelligence Group disabled the Google accounts NetNut allegedly used for malware command and control, shared technical detail on its SDKs with other platform providers and law enforcement, and used Play Protect, Android's built-in security, to disable apps known to carry NetNut code. Lumen's Black Lotus Labs and the Shadowserver Foundation were named as partners in the operation.

The seizure followed reporting by KrebsOnSecurity, which connected NetNut to a botnet that researchers had been tracking under the name "Popa." The distinction matters, so be precise about it: the botnet is Popa, and NetNut is the proxy service that allegedly monetized Popa's infected devices. Investigators did not move on NetNut because it sold proxies. They moved because of where a large part of its proxy pool allegedly came from. For its part, Alarum says it is itself investigating whether third parties abused its network, and that as of July 3 it had not been formally contacted by the FBI.

Popa: two million hijacked living rooms

According to KrebsOnSecurity and Google's Threat Intelligence Group, the Popa botnet runs on an estimated 2 million or more devices worldwide. Lumen's Black Lotus Labs measured between 1.5 and 2.5 million distinct IP addresses phoning in each day. It did not spread through some exotic zero-day. It spread through apps: ordinary-looking software that bundled an SDK, which NetNut characterizes as designed to use only a small slice of a device's bandwidth. (An SDK is a code package a developer drops into an app to add a feature. Here, the feature was turning your device into someone else's proxy.) Krebs reported the SDKs concentrated on home entertainment hardware, Android-based TV boxes plus a meaningful share of apps for LG webOS and Samsung Tizen smart TVs.

Once one of those apps was installed, the device could quietly act as a residential proxy exit node. Every scrape, ad-fraud impression, and account-takeover attempt a NetNut customer pushed through that node came out of a real family's smart TV, wearing that household's IP address. That is the entire appeal of residential proxies to the buyer, and the entire problem with sourcing them this way: the traffic looks human because it is literally coming out of a human's living room, except, researchers say, the human never agreed to any of it. "Account takeover" here means attackers using those clean-looking home IPs to log into other people's accounts, and "ad fraud" means faking real viewers to drain advertising budgets. Neither is a victimless side effect. Both are the product.

Google took independent action. It disabled apps that bundled the NetNut SDK, and it reported observing 316 distinct threat-actor clusters using suspected NetNut exit nodes in a single week in June, including cybercriminal and espionage groups running password-spray attacks. Read that number again: 316 separate groups, one week, one provider's exit nodes. That is what "residential proxy" quietly meant on this network.

Alarum rejects this framing, and its objection belongs in the record. The company says its SDKs run with notice and consent, that they "do not transform user devices into malware-controlled systems," and that the security firms' reports contain "demonstrably inaccurate assertions and flawed deductions rather than verified facts." That dispute is real and worth stating plainly. It is also, so far, one company's position against the published findings of Krebs, Google, and multiple independent security firms, and against a federal domain seizure.

Follow the ownership: Alarum Technologies (Nasdaq: ALAR)

NetNut is not some anonymous offshore shell. Per Alarum's own filings, NetNut Ltd. is a subsidiary of Alarum Technologies Ltd., a Tel Aviv company listed on the Nasdaq under the ticker ALAR. Alarum was previously named Safe-T Group, and it acquired NetNut in 2019. This is a regulated, publicly traded company with a proxy business at its center.

The market reaction was fast. Alarum stock fell to $2.62 a share by July 8, 2026, a decline of roughly 67% over the week, erasing about two-thirds of the company's market value. In its own disclosures, Alarum warned the disruption is "likely to have a material adverse effect" on operations if it continues. If you ever assumed that "big, established, publicly listed provider" guarantees clean sourcing, this is your answer: it does not. Scale and a stock ticker tell you nothing about how the IPs got into the pool. We mapped the industry's real corporate structure, rebrands and holding companies included, in who owns your proxy provider.

A fair note on where this stands: this is an active investigation, not a court verdict. Alarum denies the botnet characterization, says it had not been formally contacted by the FBI as of July 3, and says it will cooperate with law enforcement. Investigations like this can run for a long time, and some end without charges. What is not in dispute is that the domains were seized, the network was disrupted, and the sourcing question is now the company's central problem.

A timeline of the takedown

  • June 18, 2026: KrebsOnSecurity publishes an investigation tying the Popa botnet to NetNut and Alarum, drawing on research from multiple security firms.
  • July 2, 2026: The FBI and IRS Criminal Investigation seize NetNut domains and post a seizure notice. Google's Threat Intelligence Group publishes its disruption report the same day, and Alarum discloses the seizure to investors.
  • July 3, 2026: Alarum says additional domains were seized, warns of a possible "material adverse effect," and states neither it nor NetNut has been formally contacted by the FBI.
  • July 4, 2026: Alarum pauses traffic through the affected services "for several days" to investigate, saying it is working to restore normal operations.
  • July 6, 2026: The Justice Department publicly confirms the seizure.
  • July 8, 2026: netnut.io is also carrying a seizure notice, and ALAR trades at $2.62, down about 67% on the week.
  • July 13, 2026: Alarum says the root cause is still unknown, appoints an external forensic team, cuts about a third of its workforce, and says it is evaluating a controlled restart with no final conclusions yet on whether third parties misused its network.

The one spec that decides everything: sourcing

Every honest conversation about residential proxies eventually lands on the same question, and almost every marketing page dodges it: how did these IPs get into the pool? There are really only two answers, and they could not be further apart.

Consented sourcingHijacked sourcing (the alleged NetNut/Popa model)
How the device joinsOwner opts in: a paid app, a rewards program, or a clearly disclosed SDKA secret SDK slipped into an app, or outright malware
Does the owner know?Yes, it is disclosedNo
Can they leave?Yes, uninstall or opt outNot knowingly, they do not know they are in it
What you rentTraffic the owner agreed to shareA stranger's hijacked device
Reputation you inheritThe pool's own, kept clean on purposeThe same IPs used for ad fraud and account takeover
Legal exposureA normal commercial serviceRenting infrastructure built from a crime

The difference is not cosmetic. When you route a request through a residential proxy, you inherit that exit node's reputation. If 316 suspected threat-actor clusters spent the week running ad fraud and account takeover through the same NetNut nodes you are renting, then to every fraud-detection system on the internet your traffic looks exactly like theirs. We wrote a whole breakdown of how websites detect proxies, and IP reputation sits near the top of that list. A botnet-sourced pool is pre-burned before you send a single request, which is the practical reason sourcing is not an ethics footnote: it is a performance spec too.

Why "free residential" is where this hides

Here is the uncomfortable part for anyone hunting a bargain. The NetNut model (get onto real devices through bundled SDKs, then rent them out) is exactly how most "free residential proxy" pools are built. Residential IPs cost real money to acquire honestly, so when someone hands them out for free, the device owners are usually the ones paying, without ever knowing it.

This is the distinction people miss. Most free proxies you find on a list are datacenter IPs, not residential at all. In our own study of 47 million proxy checks, the free pool is overwhelmingly datacenter, and those IPs die within minutes to hours with only a small fraction alive at any given moment. But the "free residential" category specifically is a different animal, and it is far more likely to be someone's home connection turned into an exit node without consent. We take that trap apart in free residential proxies: what is real and what is a trap, and the broader safety mechanics in are free proxies safe. NetNut is that same trap at industrial scale, with a Nasdaq ticker bolted on.

If you want the plain definition of what a residential IP even is and why it carries value, we cover it in what is a residential proxy. The short version: the value comes entirely from the IP belonging to a real ISP customer. The NetNut case is what happens when the industry chases that value and stops caring how it gets the customer's IP.

NetNut is not the first, and the pattern is documented

If this feels like a one-off, it is not. The residential-proxy-built-from-hijacked-devices model has a paper trail, in both law enforcement records and peer-reviewed research.

In May 2024, the U.S. Justice Department dismantled a residential proxy botnet called 911 S5, which the FBI called "likely the world's largest botnet ever." Court documents put it at more than 19 million hijacked IP addresses across nearly 200 countries, built from residential Windows computers infected through bundled software and free VPN apps, then resold as "residential" proxies. Its administrator, YunHe Wang, was arrested on May 24, 2024, and the Treasury sanctioned him and two associates. The government said the network was used to bypass fraud detection and steal billions, including more than $5.9 billion tied to fraudulent pandemic and unemployment claims. Same shape as NetNut and Popa: real consumer devices, turned into exit nodes, rented to whoever paid.

The academic side saw it coming. Back in 2019, researchers led by Xianghang Mi published "Resident Evil: Understanding Residential IP Proxy as a Dark Service" at the IEEE Symposium on Security and Privacy, one of the field's top venues. Studying about 6 million residential IPs across 230-plus countries, they found that providers claim their hosts "willingly joined," yet "many proxies run on likely compromised hosts including IoT devices," and that the same pools carried illegal promotion, fast fluxing, phishing, and malware hosting. NetNut and Popa is that 2019 warning at industrial scale, seven years later, with a stock ticker attached.

What this means if you were a NetNut customer

If you were routing traffic through NetNut, two things are true at once. First, the service is degraded or down: with the domains seized and the network disrupted, the endpoints your tooling pointed at broke on July 2, and Alarum paused traffic through the affected services while it investigates. Second, and more important long term, every request you sent through those exit nodes shared IP space with the 316 suspected clusters Google counted in a single June week. Any target you scraped or logged into from those IPs may have flagged the address already, so do not be surprised if accounts or scrapers tied to that traffic get extra scrutiny.

The move is not to scramble for the nearest "cheap residential" replacement, because that is how you land in the next Popa. The move is to switch to a pool you can actually ask questions about, and to verify what you are handed instead of trusting a label.

How to not accidentally rent a botnet

You cannot audit a provider's entire supply chain from the outside, but you can ask the questions that make a shady one squirm, and you can check the IPs you are given. Our how to vet a proxy provider guide is the full checklist.

  • Ask how the pool is sourced. A provider that sources residential IPs through consented, disclosed opt-in should be able to say so plainly. Vagueness is itself an answer.
  • Be suspicious of "free residential." Honestly sourced residential bandwidth has a real cost. Free residential almost always means the device owner is the unwitting supplier.
  • Check the network behind an IP before you trust it. Our free proxy checker makes a real connection through a proxy and reports the exit location, the anonymity grade, and the network the IP actually belongs to, so a datacenter IP wearing a "residential" label gets caught on the spot.
  • Watch the reputation signal. If an IP is already flagged across fraud databases, you are renting straight into someone else's mess, and the target site sees it before you do.

None of this makes residential proxies bad. It makes unsourced residential proxies bad. The technology is neutral. The supply chain is where the crime lives, and NetNut is the proof.

The honest takeaway

The NetNut case is not a story about proxies being evil. It is a story about one specific, avoidable failure: allegedly renting out real people's devices without their consent and dressing it up as a normal product. A Nasdaq-listed company is alleged to have done it at two-million-device scale, Google says it watched 316 threat clusters pour through the result in a single week, and the FBI and IRS-CI seized the domains. The company disputes the botnet label, and the investigation is not finished. But you do not need a verdict to take the lesson, because the lesson is about the question, not the defendant: for anyone buying proxies, sourcing is not a footnote, it is the product.

If you just need to test the machinery or run a low-stakes, throwaway task, our free proxy list re-checks and refreshes every few minutes across 100+ countries and HTTP, HTTPS, SOCKS4, and SOCKS5, and it is honest about what it is (mostly short-lived datacenter IPs, verified live). When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC, and the whole point of this article is the thing we would rather compete on: being able to tell you where they come from.

Sources

Frequently asked questions

What is the NetNut botnet?
NetNut is a residential proxy service, and the "NetNut botnet" refers to the Popa botnet that security researchers and KrebsOnSecurity tied to it. According to Krebs and Google's Threat Intelligence Group, Popa runs on an estimated 2 million or more smart TVs and streaming boxes through apps that bundled NetNut's SDK, turning each device into a residential proxy exit node. On July 2, 2026, the FBI and IRS Criminal Investigation seized hundreds of NetNut domains, including netnut.com and netnut.io. NetNut's parent, Alarum Technologies, disputes the botnet characterization.
Is NetNut shut down?
Its main domains were seized. On July 2, 2026, the FBI and IRS-CI seized hundreds of NetNut domains including netnut.com and netnut.io, and the public-facing service went dark. NetNut is operated by Alarum Technologies (Nasdaq: ALAR), whose stock fell about 67% to $2.62 by July 8, 2026. Alarum paused traffic through the affected network, warned of a material impact on its business, and by July 13 said the root cause was still unknown, cut about a third of its workforce, and was evaluating a controlled restart.
Who owns NetNut?
NetNut is operated by Alarum Technologies, an Israeli public company listed on the Nasdaq as ALAR and previously known as Safe-T Group. Alarum acquired NetNut in 2019, and its own filings describe NetNut Ltd. as a subsidiary. This was not an anonymous offshore operation: a regulated, publicly traded company had the proxy business at its center.
How were smart TVs turned into proxies?
Through bundled SDKs. Per KrebsOnSecurity and Google, ordinary-looking apps included NetNut's SDK, and once installed on a smart TV or streaming box that code could turn the device into a residential proxy exit node. Google later disabled apps carrying the SDK and reported seeing 316 suspected threat-actor clusters using NetNut exit nodes in a single June week. Researchers say the device owners were never meaningfully asked. Alarum says its SDKs run with notice and consent.
Does Alarum admit NetNut is a botnet?
No. Alarum Technologies, NetNut's parent, disputes it. The company says its SDKs operate with notice and consent and do not turn devices into malware-controlled systems, and it called the security firms' reports inaccurate assertions and flawed deductions rather than verified facts. It also said that as of July 3, 2026 it had not been formally contacted by the FBI, and that it would cooperate with law enforcement. The botnet link is the conclusion of Krebs, Google, and several security firms, and the matter is under investigation, not settled in court.
How do I know my residential proxies aren't sourced from a botnet?
Ask the provider how the pool is sourced and treat vague answers as a red flag, because consented, disclosed opt-in is the standard to look for. Be especially wary of "free residential," which almost always means someone's device is the unwitting supplier. You can also verify any IP you are given with a proxy checker to see the real network behind it and whether it already carries a bad reputation.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires.

47M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup