The NetNut takedown became public on July 2, 2026, when the FBI and IRS Criminal Investigation seized hundreds of NetNut domains (netnut.com and netnut.io among them) in a coordinated action with Google. The seizure followed reporting by KrebsOnSecurity, which in June tied the NetNut residential proxy service to a botnet that researchers track as "Popa," allegedly built from more than 2 million hijacked smart TVs and streaming boxes and quietly rented out as residential proxy exit nodes. NetNut's parent company disputes that characterization. Either way, the case is the clearest example yet of why the only proxy spec that actually matters is where the IPs come from.
We run a proxy network, so this one is close to home. A residential proxy is only ever as clean as the way its IPs were sourced, and the NetNut case is what happens when nobody asks that question hard enough. Here is what is confirmed, what is still alleged, who owns what, and how to make sure the pool you are paying for is not a botnet with a billing page.
The NetNut takedown, by the numbers
- 2M+
- Hijacked devices (Popa botnet)
- smart TVs and streaming boxes, estimated
- 316
- Threat-actor clusters in one June week
- using NetNut exit nodes, per Google
- $2.62
- Alarum (ALAR) share price, July 8
- down about 67% on the week
- $11.7M
- Alarum Q1 2026 revenue
- up 64% year over year
Source: KrebsOnSecurity, Google Threat Intelligence Group, and Alarum SEC filings (2026)
What the FBI actually seized
On July 2, 2026, the FBI and IRS Criminal Investigation (IRS-CI) seized hundreds of domains belonging to NetNut, including its main sites netnut.com and netnut.io, and replaced them with a government seizure notice. The Justice Department publicly confirmed the seizure later that week. NetNut was one of the larger names in the residential proxy market, the kind of provider that sells access to millions of "real" home IP addresses for scraping, ad verification, and similar work. This was not a fly-by-night operation: its parent reported $11.7 million in revenue in the first quarter of 2026, up 64% from a year earlier.
The action was coordinated. Google's Threat Intelligence Group disabled the Google accounts NetNut allegedly used for malware command and control, shared technical detail on its SDKs with other platform providers and law enforcement, and used Play Protect, Android's built-in security, to disable apps known to carry NetNut code. Lumen's Black Lotus Labs and the Shadowserver Foundation were named as partners in the operation.
The seizure followed reporting by KrebsOnSecurity, which connected NetNut to a botnet that researchers had been tracking under the name "Popa." The distinction matters, so be precise about it: the botnet is Popa, and NetNut is the proxy service that allegedly monetized Popa's infected devices. Investigators did not move on NetNut because it sold proxies. They moved because of where a large part of its proxy pool allegedly came from. For its part, Alarum says it is itself investigating whether third parties abused its network, and that as of July 3 it had not been formally contacted by the FBI.
Popa: two million hijacked living rooms
According to KrebsOnSecurity and Google's Threat Intelligence Group, the Popa botnet runs on an estimated 2 million or more devices worldwide. Lumen's Black Lotus Labs measured between 1.5 and 2.5 million distinct IP addresses phoning in each day. It did not spread through some exotic zero-day. It spread through apps: ordinary-looking software that bundled an SDK, which NetNut characterizes as designed to use only a small slice of a device's bandwidth. (An SDK is a code package a developer drops into an app to add a feature. Here, the feature was turning your device into someone else's proxy.) Krebs reported the SDKs concentrated on home entertainment hardware, Android-based TV boxes plus a meaningful share of apps for LG webOS and Samsung Tizen smart TVs.
Once one of those apps was installed, the device could quietly act as a residential proxy exit node. Every scrape, ad-fraud impression, and account-takeover attempt a NetNut customer pushed through that node came out of a real family's smart TV, wearing that household's IP address. That is the entire appeal of residential proxies to the buyer, and the entire problem with sourcing them this way: the traffic looks human because it is literally coming out of a human's living room, except, researchers say, the human never agreed to any of it. "Account takeover" here means attackers using those clean-looking home IPs to log into other people's accounts, and "ad fraud" means faking real viewers to drain advertising budgets. Neither is a victimless side effect. Both are the product.
Google took independent action. It disabled apps that bundled the NetNut SDK, and it reported observing 316 distinct threat-actor clusters using suspected NetNut exit nodes in a single week in June, including cybercriminal and espionage groups running password-spray attacks. Read that number again: 316 separate groups, one week, one provider's exit nodes. That is what "residential proxy" quietly meant on this network.
Alarum rejects this framing, and its objection belongs in the record. The company says its SDKs run with notice and consent, that they "do not transform user devices into malware-controlled systems," and that the security firms' reports contain "demonstrably inaccurate assertions and flawed deductions rather than verified facts." That dispute is real and worth stating plainly. It is also, so far, one company's position against the published findings of Krebs, Google, and multiple independent security firms, and against a federal domain seizure.
Follow the ownership: Alarum Technologies (Nasdaq: ALAR)
NetNut is not some anonymous offshore shell. Per Alarum's own filings, NetNut Ltd. is a subsidiary of Alarum Technologies Ltd., a Tel Aviv company listed on the Nasdaq under the ticker ALAR. Alarum was previously named Safe-T Group, and it acquired NetNut in 2019. This is a regulated, publicly traded company with a proxy business at its center.
The market reaction was fast. Alarum stock fell to $2.62 a share by July 8, 2026, a decline of roughly 67% over the week, erasing about two-thirds of the company's market value. In its own disclosures, Alarum warned the disruption is "likely to have a material adverse effect" on operations if it continues. If you ever assumed that "big, established, publicly listed provider" guarantees clean sourcing, this is your answer: it does not. Scale and a stock ticker tell you nothing about how the IPs got into the pool. We mapped the industry's real corporate structure, rebrands and holding companies included, in who owns your proxy provider.
A fair note on where this stands: this is an active investigation, not a court verdict. Alarum denies the botnet characterization, says it had not been formally contacted by the FBI as of July 3, and says it will cooperate with law enforcement. Investigations like this can run for a long time, and some end without charges. What is not in dispute is that the domains were seized, the network was disrupted, and the sourcing question is now the company's central problem.
A timeline of the takedown
- June 18, 2026: KrebsOnSecurity publishes an investigation tying the Popa botnet to NetNut and Alarum, drawing on research from multiple security firms.
- July 2, 2026: The FBI and IRS Criminal Investigation seize NetNut domains and post a seizure notice. Google's Threat Intelligence Group publishes its disruption report the same day, and Alarum discloses the seizure to investors.
- July 3, 2026: Alarum says additional domains were seized, warns of a possible "material adverse effect," and states neither it nor NetNut has been formally contacted by the FBI.
- July 4, 2026: Alarum pauses traffic through the affected services "for several days" to investigate, saying it is working to restore normal operations.
- July 6, 2026: The Justice Department publicly confirms the seizure.
- July 8, 2026: netnut.io is also carrying a seizure notice, and ALAR trades at $2.62, down about 67% on the week.
- July 13, 2026: Alarum says the root cause is still unknown, appoints an external forensic team, cuts about a third of its workforce, and says it is evaluating a controlled restart with no final conclusions yet on whether third parties misused its network.
The one spec that decides everything: sourcing
Every honest conversation about residential proxies eventually lands on the same question, and almost every marketing page dodges it: how did these IPs get into the pool? There are really only two answers, and they could not be further apart.
| Consented sourcing | Hijacked sourcing (the alleged NetNut/Popa model) | |
|---|---|---|
| How the device joins | Owner opts in: a paid app, a rewards program, or a clearly disclosed SDK | A secret SDK slipped into an app, or outright malware |
| Does the owner know? | Yes, it is disclosed | No |
| Can they leave? | Yes, uninstall or opt out | Not knowingly, they do not know they are in it |
| What you rent | Traffic the owner agreed to share | A stranger's hijacked device |
| Reputation you inherit | The pool's own, kept clean on purpose | The same IPs used for ad fraud and account takeover |
| Legal exposure | A normal commercial service | Renting infrastructure built from a crime |
The difference is not cosmetic. When you route a request through a residential proxy, you inherit that exit node's reputation. If 316 suspected threat-actor clusters spent the week running ad fraud and account takeover through the same NetNut nodes you are renting, then to every fraud-detection system on the internet your traffic looks exactly like theirs. We wrote a whole breakdown of how websites detect proxies, and IP reputation sits near the top of that list. A botnet-sourced pool is pre-burned before you send a single request, which is the practical reason sourcing is not an ethics footnote: it is a performance spec too.
Why "free residential" is where this hides
Here is the uncomfortable part for anyone hunting a bargain. The NetNut model (get onto real devices through bundled SDKs, then rent them out) is exactly how most "free residential proxy" pools are built. Residential IPs cost real money to acquire honestly, so when someone hands them out for free, the device owners are usually the ones paying, without ever knowing it.
This is the distinction people miss. Most free proxies you find on a list are datacenter IPs, not residential at all. In our own study of 47 million proxy checks, the free pool is overwhelmingly datacenter, and those IPs die within minutes to hours with only a small fraction alive at any given moment. But the "free residential" category specifically is a different animal, and it is far more likely to be someone's home connection turned into an exit node without consent. We take that trap apart in free residential proxies: what is real and what is a trap, and the broader safety mechanics in are free proxies safe. NetNut is that same trap at industrial scale, with a Nasdaq ticker bolted on.
If you want the plain definition of what a residential IP even is and why it carries value, we cover it in what is a residential proxy. The short version: the value comes entirely from the IP belonging to a real ISP customer. The NetNut case is what happens when the industry chases that value and stops caring how it gets the customer's IP.
NetNut is not the first, and the pattern is documented
If this feels like a one-off, it is not. The residential-proxy-built-from-hijacked-devices model has a paper trail, in both law enforcement records and peer-reviewed research.
In May 2024, the U.S. Justice Department dismantled a residential proxy botnet called 911 S5, which the FBI called "likely the world's largest botnet ever." Court documents put it at more than 19 million hijacked IP addresses across nearly 200 countries, built from residential Windows computers infected through bundled software and free VPN apps, then resold as "residential" proxies. Its administrator, YunHe Wang, was arrested on May 24, 2024, and the Treasury sanctioned him and two associates. The government said the network was used to bypass fraud detection and steal billions, including more than $5.9 billion tied to fraudulent pandemic and unemployment claims. Same shape as NetNut and Popa: real consumer devices, turned into exit nodes, rented to whoever paid.
The academic side saw it coming. Back in 2019, researchers led by Xianghang Mi published "Resident Evil: Understanding Residential IP Proxy as a Dark Service" at the IEEE Symposium on Security and Privacy, one of the field's top venues. Studying about 6 million residential IPs across 230-plus countries, they found that providers claim their hosts "willingly joined," yet "many proxies run on likely compromised hosts including IoT devices," and that the same pools carried illegal promotion, fast fluxing, phishing, and malware hosting. NetNut and Popa is that 2019 warning at industrial scale, seven years later, with a stock ticker attached.
What this means if you were a NetNut customer
If you were routing traffic through NetNut, two things are true at once. First, the service is degraded or down: with the domains seized and the network disrupted, the endpoints your tooling pointed at broke on July 2, and Alarum paused traffic through the affected services while it investigates. Second, and more important long term, every request you sent through those exit nodes shared IP space with the 316 suspected clusters Google counted in a single June week. Any target you scraped or logged into from those IPs may have flagged the address already, so do not be surprised if accounts or scrapers tied to that traffic get extra scrutiny.
The move is not to scramble for the nearest "cheap residential" replacement, because that is how you land in the next Popa. The move is to switch to a pool you can actually ask questions about, and to verify what you are handed instead of trusting a label.
How to not accidentally rent a botnet
You cannot audit a provider's entire supply chain from the outside, but you can ask the questions that make a shady one squirm, and you can check the IPs you are given. Our how to vet a proxy provider guide is the full checklist.
- Ask how the pool is sourced. A provider that sources residential IPs through consented, disclosed opt-in should be able to say so plainly. Vagueness is itself an answer.
- Be suspicious of "free residential." Honestly sourced residential bandwidth has a real cost. Free residential almost always means the device owner is the unwitting supplier.
- Check the network behind an IP before you trust it. Our free proxy checker makes a real connection through a proxy and reports the exit location, the anonymity grade, and the network the IP actually belongs to, so a datacenter IP wearing a "residential" label gets caught on the spot.
- Watch the reputation signal. If an IP is already flagged across fraud databases, you are renting straight into someone else's mess, and the target site sees it before you do.
None of this makes residential proxies bad. It makes unsourced residential proxies bad. The technology is neutral. The supply chain is where the crime lives, and NetNut is the proof.
The honest takeaway
The NetNut case is not a story about proxies being evil. It is a story about one specific, avoidable failure: allegedly renting out real people's devices without their consent and dressing it up as a normal product. A Nasdaq-listed company is alleged to have done it at two-million-device scale, Google says it watched 316 threat clusters pour through the result in a single week, and the FBI and IRS-CI seized the domains. The company disputes the botnet label, and the investigation is not finished. But you do not need a verdict to take the lesson, because the lesson is about the question, not the defendant: for anyone buying proxies, sourcing is not a footnote, it is the product.
If you just need to test the machinery or run a low-stakes, throwaway task, our free proxy list re-checks and refreshes every few minutes across 100+ countries and HTTP, HTTPS, SOCKS4, and SOCKS5, and it is honest about what it is (mostly short-lived datacenter IPs, verified live). When you need residential IPs that hold up, we sell them at $0.65/GB pay as you go with no KYC, and the whole point of this article is the thing we would rather compete on: being able to tell you where they come from.
Sources
- KrebsOnSecurity, "'Popa' Botnet Linked to Publicly-Traded Israeli Firm" (June 18, 2026)
- KrebsOnSecurity, "FBI Seizes NetNut Proxy Platform, Popa Botnet" (July 2026)
- Google Threat Intelligence Group, "Google's Continued Disruption of Malicious Residential Proxy Networks" (July 2, 2026)
- Alarum Technologies Ltd., "Alarum Technologies Provides Update Regarding Recent Law Enforcement Action", SEC EDGAR Form 6-K exhibit (July 3, 2026)
- SEC EDGAR, Alarum Technologies Ltd. company filing record (CIK 0001725332, listed as "formerly: Safe-T Group Ltd.")
- Alarum Technologies Ltd., "Alarum Technologies Provides Further Update Regarding Recent Developments" (July 13, 2026)
- Alarum Technologies Ltd., "Temporary Operational Pause of Certain Network Services" (July 4, 2026)
- Insurance Journal, "FBI Probes Whether Alarum Unit Is Behind Co-Opted Home Devices" (July 6, 2026)
- BleepingComputer, "NetNut proxy network disrupted, 2 million infected devices cut off" (July 2026)
- U.S. Department of Justice, "911 S5 Botnet Dismantled and Its Administrator Arrested in Coordinated International Operation" (May 29, 2024)
- Xianghang Mi et al., "Resident Evil: Understanding Residential IP Proxy as a Dark Service", 2019 IEEE Symposium on Security and Privacy