The FBI seized hundreds of domains operated by NetNut, a residential proxy service run by Israeli publicly-traded firm Alarum Technologies, following evidence linking the platform to the Popa botnet. The action, executed with industry partners, targets infrastructure that security researchers connected to the compromise of at least two million devices.
NetNut marketed itself as a legitimate proxy service for web scraping and market research. The platform instead functioned as a distribution mechanism for Popa malware, which infected millions of computers without meaningful user consent. Victims' devices were conscripted into a botnet and their internet connections sold as "residential proxies" to clients seeking to mask their online activity.
The seizure follows a KrebsOnSecurity investigation published roughly two weeks prior, which detailed findings from multiple security firms documenting NetNut's connection to Popa. That reporting exposed how the service collected compromised devices at scale and monetized their bandwidth through proxy rental arrangements.
Residential proxies derived from botnet traffic carry distinct risks. Organizations purchasing these services unknowingly route requests through infected machines, creating legal liability for participating in distributed fraud schemes. Companies conducting legitimate web scraping or ad verification face reputational damage when their infrastructure connects to compromised hosts. Meanwhile, individuals whose devices power these botnets experience degraded performance, increased bandwidth consumption, and exposure to law enforcement scrutiny.
Alarum Technologies operates as a legitimate entity on Nasdaq, which raises questions about oversight of subsidiary operations and financial disclosure obligations regarding Popa-related revenue. The company faces potential shareholder liability and regulatory investigation into whether executives understood the botnet connection.
The FBI action represents enforcement against infrastructure explicitly designed to monetize compromised devices. Residential proxy services continue operating legally, but this seizure establishes precedent that platforms profiting from botnet traffic face federal intervention. Organizations must audit proxy service providers and verify device legitimacy before contr