FBI Seizes NetNut Proxy Service in Botnet Crackdown
Law enforcement targets infrastructure used to disguise malicious traffic as legitimate residential connections.
Hundreds of Domains Seized
The FBI has seized hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies. The action follows reports linking NetNut to the Popa botnet, which routes malicious traffic through compromised home routers and devices.
Residential proxies let attackers mask their location by routing requests through legitimate IP addresses. Security researchers have long warned that some proxy services knowingly facilitate criminal activity while marketing themselves as tools for web scraping and ad verification.
The Popa Connection
Security firms traced NetNut infrastructure to Popa, a botnet that infected consumer devices to create a vast proxy network. Device owners typically have no idea their bandwidth is being sold or used for attacks.
The FBI's move comes weeks after detailed technical reporting on the connection. The seizure disrupts a key revenue stream for the botnet operators while alerting consumers to the risks of compromised routers.
Publicly Traded Company Implicated
Alarum Technologies trades on NASDAQ, making this one of the rare cases where a public company faces action over proxy service abuse. The company has not yet commented on the seizures.
The case raises questions about due diligence in the proxy industry, where the line between legitimate business use and criminal infrastructure remains blurry.