The FBI seized hundreds of domains operated by NetNut, a residential proxy service run by publicly-traded Israeli firm Alarum Technologies. The action follows revelations that NetNut infrastructure connected to the Popa botnet, which compromises at least two million devices without user consent.

Residential proxies route internet traffic through real consumer devices, typically without explicit knowledge or permission. NetNut marketed these services to businesses for price monitoring, ad verification, and market research. Security researchers discovered the platform operated in tandem with Popa malware, which infected millions of machines and harvested their bandwidth for proxy services.

Botnet operators inject malware onto victim devices, then monetize the stolen computational resources by selling proxy access to paying customers. Users whose machines became part of Popa experienced degraded performance, increased bandwidth consumption, and elevated security risks. The infected devices served as intermediaries for third-party traffic, potentially exposing victims to legal liability if their IP addresses were used for fraud, scraping, or other malicious activity.

Alarum Technologies maintained the service operated legitimately, but the infrastructure enabled widespread device compromise at scale. The FBI coordinated with international partners and industry stakeholders to disrupt the operation. Domain seizure prevents customers from accessing the proxy network and blocks new device recruitment.

This enforcement action underscores the murky legal territory residential proxy services occupy. While some operate transparently with genuine user consent, others blur the line between legitimate network infrastructure and botnet operations. Victims discovered their machines were being weaponized without meaningful disclosure or compensation.

Organizations using proxy services now face heightened scrutiny. Purchasing bandwidth from platforms connected to compromised devices exposes companies to legal risk and reputational damage. The seizure signals law enforcement intent to prosecute operators who profit from non-consensual device compromise, regardless of corporate structure or public trading status.