FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors
Google and the FBI disrupted the NetNut residential proxy network, which used a Popa botnet embedded in Android-based smart TVs. Google said at least 316 threat clusters used NetNut exit nodes for attacks in one week in June 2026, and it disabled related accounts and Play Protect protections. Reporting links NetNut to NASDAQ-listed Alarum Technologies, according to Krebs and other investigators.
How this was made

The 30-second read
Why it matters
Google disabled NetNut-linked Google accounts, updated Play Protect warnings, and disabled apps with the compromised SDKs alongside FBI legal actions; the article frames this as degrading NetNut’s device pool by millions.
Market read
Traders may reassess legal/regulatory and reputational risk for any public company credibly tied to the dismantled proxy infrastructure, with potential near-term volatility driven by enforcement headlines.
What to watch
No quantified revenue exposure, no confirmed ownership of NetNut domains beyond seizure confusion, and no mention of whether Alarum’s product is still actively used or already mitigated—these could temper immediate valuation effects.
Background
NetNut allegedly used a Popa botnet embedded in off-brand Android smart TVs to turn home IPs into residential proxy exit nodes.
Ticker impact
Article links NetNut’s Popa SDK developers to Alarum Technologies and says FBI seizure and Google mitigations target NetNut infrastructure tied to Alarum’s leadership.
Bias to negative/volatile near-term trading on any investor perception of material disruption or legal exposure.
The piece asserts direct links between Alarum leadership and Popa SDK developers, and describes coordinated takedown/mitigation actions degrading NetNut’s device pool; however, it does not quantify financial impact or confirm Alarum’s current revenue exposure.
Market effects
Highlights heightened platform enforcement (Google Play Protect, account disablement) against Android-based malware/proxy tooling, raising compliance and reputational risk for adjacent cybersecurity/proxy vendors.
Israeli tech names with US listings may see spillover risk if linked to cybercrime infrastructure in US enforcement actions.
Demonstrates cross-border takedown dynamics (FBI + Google) that can rapidly degrade botnet/proxy supply chains worldwide.
Counterpoint
Even if Alarum is linked to developers, the article provides no evidence of current operational control of NetNut; market impact may be limited unless regulators or courts allege ongoing wrongdoing.
Key entities
- cybercrime infrastructureNetNut
Residential proxy network allegedly powered by the Popa botnet and used for credential stuffing, password spraying, fraud, and scraping.
- malware/botnetPopa botnet
Stealth communications layer embedded via deceptive SDKs into Android-based smart TVs and related apps.
- public companyAlarum Technologies Ltd
Israeli firm listed on NASDAQ; article claims links between its executive leadership and Popa SDK developers.
- law enforcementFBI
Seized certain domains associated with NetNut as part of the takedown.
- platform operatorGoogle
Deployed technical mitigations (account disablement, Play Protect updates, app disablement) to degrade NetNut’s command-and-control and device pool.



