FBI Seizes NetNut Proxy Service in Botnet Crackdown

Law enforcement targets infrastructure used to disguise malicious traffic as legitimate residential connections.

Abstract network disruption representing infrastructure seizure
AI-generated illustration · Sylvaris

Hundreds of Domains Seized

The FBI has seized hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies. The action follows reports linking NetNut to the Popa botnet, which routes malicious traffic through compromised home routers and devices.

Residential proxies let attackers mask their location by routing requests through legitimate IP addresses. Security researchers have long warned that some proxy services knowingly facilitate criminal activity while marketing themselves as tools for web scraping and ad verification.

The Popa Connection

Security firms traced NetNut infrastructure to Popa, a botnet that infected consumer devices to create a vast proxy network. Device owners typically have no idea their bandwidth is being sold or used for attacks.

The FBI's move comes weeks after detailed technical reporting on the connection. The seizure disrupts a key revenue stream for the botnet operators while alerting consumers to the risks of compromised routers.

Publicly Traded Company Implicated

Alarum Technologies trades on NASDAQ, making this one of the rare cases where a public company faces action over proxy service abuse. The company has not yet commented on the seizures.

The case raises questions about due diligence in the proxy industry, where the line between legitimate business use and criminal infrastructure remains blurry.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.