FBI Takes Down NetNut Proxy Network Tied to Popa Botnet
The FBI announced it has seized hundreds of domains connected to NetNut, a large residential proxy service run by Alarum Technologies, a company publicly traded on the Nasdaq under the ticker ALAR. Residential proxy services like NetNut let customers route their internet traffic through the home IP addresses of everyday users, often marketed for legitimate purposes like ad verification or market research, but frequently abused to mask fraud, scraping, and other malicious activity.
The seizure follows a report published roughly two weeks earlier by security journalist Brian Krebs, which cited multiple research firms linking NetNut's infrastructure to the Popa botnet. That botnet is believed to have quietly compromised at least two million consumer devices, turning them into unwitting exit nodes for proxy traffic without meaningful user consent.
Details on how the FBI coordinated the takedown, and what happens next for Alarum Technologies, remain limited, but the action signals that law enforcement is increasingly willing to target the business side of the residential proxy industry rather than just the malware distributors who build these botnets.