A coordinated law enforcement and industry action has dismantled a residential proxy service linked to at least two million compromised consumer devices.
Summary
- The FBI and IRS Criminal Investigation seized hundreds of domains tied to NetNut and the Popa botnet, operated by NASDAQ-listed Alarum Technologies.
- The Popa botnet silently enrolled at least two million consumer devices — including smart TVs and streaming boxes — as always-on proxy nodes without meaningful user consent.
- In a single week during June 2026, Google’s threat intelligence team observed 316 distinct threat actor clusters using NetNut exit nodes for activities including password spraying and traffic obfuscation.
- Many popular residential proxy brands are believed to be white-labelling the NetNut network, meaning disruption may ripple broadly across the proxy ecosystem.
- Research shows 42 percent of apps on LG smart TV’s webOS platform and more than a quarter of Samsung Tizen apps contain SDKs that enrol televisions as proxy nodes.
What happened
The FBI, working alongside the IRS Criminal Investigation division and industry partners including Google, Lumen, and Shadowserver, has seized hundreds of domains associated with NetNut, a residential proxy platform operated by Israeli-listed company Alarum Technologies. The seizure banner appeared on NetNut’s homepage, confirming the action. Alarum’s legal counsel, Omer Weiss, confirmed the company is aware of the seizure and stated it will cooperate with investigators.
The botnet behind the proxy
NetNut’s commercial proxy service was built on the Popa botnet — a collection of at least two million compromised devices, predominantly consumer streaming boxes and smart TVs running unofficial Android operating systems. The devices were enrolled as always-on proxy exit nodes, often without the owner’s meaningful knowledge or consent. Customers of the NetNut service then used those nodes to relay traffic for purposes including mass web scraping, advertising fraud, and account takeover activity.
Scale of threat actor abuse
Google’s Threat Intelligence Group (GTIG) published findings alongside the seizure, noting that in a single week during June 2026 it observed 316 distinct clusters of threat actors — spanning both cybercriminal and espionage groups — using suspected NetNut exit nodes. GTIG described the operational value to adversaries plainly: the nodes allow bad actors to mask origin IP addresses when accessing victim environments, reaching their own infrastructure, or conducting password spray attacks. Critically, because an enrolled consumer device becomes an exit node on a home network, unauthorised traffic passing through it can also expose other private devices sitting behind the same router.
Google’s parallel actions
Ahead of and alongside the FBI seizure, Google disabled Google accounts and services NetNut had been using for malware command and control. The company also shared technical intelligence on NetNut’s software development kits and backend infrastructure with platform providers, law enforcement, and research firms, and disabled apps known to bundle NetNut SDKs.
Market context: coming off the back of IPIDEA
The timing matters. Earlier this year, Google took legal action against IPIDEA, previously the largest residential proxy competitor to NetNut. Benjamin Brundage, founder of proxy-tracking service Synthient, said NetNut had grown significantly in popularity following that earlier action, reaching parity with IPIDEA on daily traffic volumes, network quality, size, and pricing. Brundage noted that the Popa botnet takedown may also reduce the capacity of large distributed denial-of-service botnets that have been built by tunnelling through residential proxy connections to compromise additional devices on home networks — a technique Synthient documented against IPIDEA’s infrastructure in January.
A resilient ecosystem
Despite the positive outcome, Google’s GTIG struck a measured note. The company assessed that proxy networks have demonstrated resilience after prior disruptions, with operators responding to degraded botnet capacity by purchasing capacity from competitors and effectively becoming resellers. GTIG concluded that a lasting impact requires scaling efforts to target the infrastructure of several interconnected providers simultaneously. Google also assessed with high confidence that many popular residential proxy brands are in fact white-labelling the NetNut botnet, meaning the ripple effects of this seizure could be broader than prior actions.
The consumer device risk is not resolved
The seizure addresses the NetNut and Popa infrastructure specifically, but the underlying exposure in consumer devices remains. Research published last month by proxy-tracking company Spur found that 42 percent of apps available on LG smart TVs via the webOS platform include SDKs that enrol the television as a residential proxy node. More than a quarter of apps on Samsung’s Tizen platform carried similar components. The problem is not limited to off-brand streaming boxes.
Why it matters
For CISOs, this takedown is significant on two levels. First, it confirms the scale at which commercial proxy services are being used by threat actors — 316 distinct clusters in a single week using one network — to obfuscate malicious traffic targeting enterprise environments, including credential-spraying campaigns. Second, it highlights that the risk surface extends beyond corporate endpoints: compromised consumer devices on employee home networks become potential lateral-movement footholds, even behind residential firewalls. Organisations with remote or hybrid workforces should consider how their threat models account for traffic originating from residential proxy exit nodes, and whether their detection logic adequately flags authentication attempts and access events sourced from such infrastructure.
What to do now
- Review authentication and access logs for activity originating from known residential proxy exit node ranges, prioritising VPN and cloud service access points.
- Ensure password spray detection controls are tuned to flag distributed, low-volume attempts sourced from residential IP ranges, not just data-centre IP blocks.
- For corporate device procurement, avoid no-name Android TV streaming boxes; where such devices exist on employee home office setups, consider guidance on replacing them with certified Android TV OS devices verified through Google’s Play Protect certification process.
- Confirm whether any internally developed or third-party mobile and smart TV applications bundle residential proxy SDKs — a concern the GTIG specifically flagged for platform providers.
- Monitor threat intelligence feeds for updated NetNut exit node lists and block or flag traffic from those ranges in perimeter and cloud security controls.
- For organisations using smart TV apps as part of digital signage or meeting room infrastructure, review whether those apps originate from the Samsung Tizen or LG webOS ecosystems given the proxy SDK prevalence findings from Spur.
