A major botnet takedown delivered rare positive news in early July. The FBI and IRS Criminal Investigation, working alongside Google, Lumen, and independent researchers, seized the infrastructure behind NetNut, a residential proxy service tied to a botnet quietly running on more than two million devices. It’s the kind of takedown that actually moves the needle, and it’s worth understanding both because it’s genuinely good news and because it points to a threat that may be sitting in your living room right now.
What Happened: A Win Against the Proxy Underworld
NetNut is a residential proxy service operated by Alarum Technologies, a publicly traded Israeli company. On the surface, proxy services like NetNut sell access to IP addresses that make traffic look like it’s coming from ordinary home internet connections, a legitimate business model used for things like ad verification and market research. The problem, as security researcher Benjamin Brundage of Synthient and Google’s Threat Intelligence Group documented, is where a large share of those “residential” IP addresses were actually coming from.
Investigators traced the botnet, nicknamed Popa, to software quietly bundled into apps on smart TVs, streaming boxes, and Android devices, much of it running without the device owner’s real knowledge or meaningful consent. Once installed, the software turned ordinary home devices into always-on proxy nodes, relaying traffic for whoever was paying for access. On July 2, 2026, visitors to NetNut’s website found something unusual waiting for them: an FBI seizure banner, in place of the company’s homepage. This botnet takedown removed a key piece of infrastructure that criminals had come to rely on.
Inside the Popa Botnet
The scale here is what makes this worth a second look. More than two million devices were pulled into the Popa botnet, most of them smart TVs and streaming boxes rather than traditional computers. Researchers found proxy SDKs baked into a striking share of apps on major platforms: over a quarter of Samsung Tizen apps analyzed, and 42% of LG webOS apps, included proxy code capable of turning a household’s smart TV into an unwitting relay point.
Once compromised, those devices weren’t just sitting idle. Google’s Threat Intelligence Group observed 316 distinct threat actor clusters using suspected NetNut infrastructure in a single week in June, routing mass web scraping, advertising fraud, and account takeover attempts through ordinary residential internet connections. That’s the appeal of a botnet like this to criminals: traffic that looks like it’s coming from someone’s living room is much harder for defenders to flag than traffic coming from a known data center. The size of the network made this botnet takedown especially significant for reducing available criminal proxy capacity.
How the Botnet Takedown Went Down
This wasn’t a single agency acting alone. The FBI and IRS Criminal Investigation led the legal action, but the operation leaned heavily on infrastructure providers and security researchers who had been tracking NetNut for months. Google, Lumen, and Shadowserver all played a role in identifying and disrupting the network, while independent researchers at Synthient supplied the tracking data that helped tie NetNut’s business to the Popa botnet’s proxy traffic.
The seizure hit both NetNut’s public-facing domains and its backend systems, though the effort wasn’t instant. The .io domain took longer to seize than the .com due to differences in jurisdiction, a reminder of how much international coordination these takedowns require. Alarum Technologies’ legal counsel said the company would “fully cooperate with law enforcement,” and the market reacted fast: Alarum’s stock dropped roughly 67% in the week following the seizure. Coordinated action across agencies and private partners made this botnet takedown possible.
Why This Botnet Takedown Counts as a Genuine Win
It’s worth pausing on why this one matters more than the average infrastructure seizure. NetNut had become one of the largest players in the residential proxy space, and its growth had accelerated earlier this year after a competing service, IPIDEA, was taken down. Criminals who lost access to IPIDEA’s network migrated toward NetNut, meaning this single action likely disrupted a meaningful share of the criminal proxy market in one move, not just one company’s slice of it.
Researchers also expect ripple effects for other criminal operations that leaned on residential proxy infrastructure to mask their activity, including large-scale DDoS botnets like Kimwolf. When the plumbing that makes an attack look legitimate gets shut off, the attacks built on top of it get harder to pull off convincingly. Successful botnet takedown operations of this scale remain uncommon and demonstrate that focused pressure can still yield results.
What This Means for You
The satisfying headline aside, there’s a practical takeaway here for anyone with a smart TV or streaming box in their home, which by now is most of us.
- Check what’s actually installed on your smart TV or streaming box. Unofficial or sideloaded Android TV apps are far more likely to carry hidden proxy code than apps from an official app store.
- Keep firmware and apps updated. Manufacturers pushing security patches after incidents like this one is part of how the ecosystem cleans itself up. Skipping updates leaves the door open longer.
- Treat “free” streaming apps with suspicion. Proxy SDKs are often bundled into apps that offer free content or unusual perks precisely because the app is monetizing your bandwidth, not just your attention.
- Remember that your home network is part of your business’s attack surface. With more employees working from home, a compromised smart TV or streaming box sharing a network with a work laptop isn’t just a personal nuisance, it’s a corporate risk.
Takedowns like this one don’t happen often, and they don’t happen without real coordination between law enforcement, infrastructure providers, and researchers willing to do the tedious work of tracing traffic back to its source. It’s a good reminder that progress against cybercrime is possible. It’s also a good reminder to check what’s quietly running on the devices plugged into your TV. Another high-impact botnet takedown would further shrink the pool of residential proxies available to attackers.
If you’d like help figuring out whether devices on your home or business network could be part of the next botnet story, Black Belt Secure can help.
Contact Black Belt Secure today for a no-obligation consultation on securing your network.
