FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors

Google and the FBI disrupted the NetNut residential proxy network, which used a Popa botnet embedded in Android-based smart TVs. Google said at least 316 threat clusters used NetNut exit nodes for attacks in one week in June 2026, and it disabled related accounts and Play Protect protections. Reporting links NetNut to NASDAQ-listed Alarum Technologies, according to Krebs and other investigators.

Original reporting
Published Jul 3, 2026, 2:00 PM UTC
Analysis
alphai AI DeskAI-generated
Added to alphai Jul 3, 2026, 2:08 PM UTC. Informational, not investment advice.
How this was made
alphai summarizes source reporting and applies a structured AI analysis for relevance, timing, sentiment and ticker impact. Always verify material claims with the original publisher.
FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors — source image
Decision brief

The 30-second read

$ALARBearishMed
01

Why it matters

Google disabled NetNut-linked Google accounts, updated Play Protect warnings, and disabled apps with the compromised SDKs alongside FBI legal actions; the article frames this as degrading NetNut’s device pool by millions.

02

Market read

Traders may reassess legal/regulatory and reputational risk for any public company credibly tied to the dismantled proxy infrastructure, with potential near-term volatility driven by enforcement headlines.

03

What to watch

No quantified revenue exposure, no confirmed ownership of NetNut domains beyond seizure confusion, and no mention of whether Alarum’s product is still actively used or already mitigated—these could temper immediate valuation effects.

Relevance 6/10Novelty 5/10Timing: after-hours/next-session read-through from FBI seizure + Google mitigations reported today

Background

NetNut allegedly used a Popa botnet embedded in off-brand Android smart TVs to turn home IPs into residential proxy exit nodes.

Company-level read

Ticker impact

$ALARBearishMedium confidence
Context

Article links NetNut’s Popa SDK developers to Alarum Technologies and says FBI seizure and Google mitigations target NetNut infrastructure tied to Alarum’s leadership.

Expected impact

Bias to negative/volatile near-term trading on any investor perception of material disruption or legal exposure.

Evidence & confidence

The piece asserts direct links between Alarum leadership and Popa SDK developers, and describes coordinated takedown/mitigation actions degrading NetNut’s device pool; however, it does not quantify financial impact or confirm Alarum’s current revenue exposure.

Market effects

Highlights heightened platform enforcement (Google Play Protect, account disablement) against Android-based malware/proxy tooling, raising compliance and reputational risk for adjacent cybersecurity/proxy vendors.

Israeli tech names with US listings may see spillover risk if linked to cybercrime infrastructure in US enforcement actions.

Demonstrates cross-border takedown dynamics (FBI + Google) that can rapidly degrade botnet/proxy supply chains worldwide.

Counterpoint

Even if Alarum is linked to developers, the article provides no evidence of current operational control of NetNut; market impact may be limited unless regulators or courts allege ongoing wrongdoing.

Key entities

  • NetNut

    Residential proxy network allegedly powered by the Popa botnet and used for credential stuffing, password spraying, fraud, and scraping.

  • Popa botnet

    Stealth communications layer embedded via deceptive SDKs into Android-based smart TVs and related apps.

  • Alarum Technologies Ltd

    Israeli firm listed on NASDAQ; article claims links between its executive leadership and Popa SDK developers.

  • FBI

    Seized certain domains associated with NetNut as part of the takedown.

  • Google

    Deployed technical mitigations (account disablement, Play Protect updates, app disablement) to degrade NetNut’s command-and-control and device pool.

Related articles

$ALARMed

Investigation launched into Alarum

Alarum Technologies said its subsidiary NetNut had multiple domains seized by the FBI, disrupting services and contributing to a sharp share-price drop from $8.02 to $3.08 over days. Alarum is investigating potential network misuse and cooperating with law enforcement. A law firm also opened a securities fraud probe for shareholders.

$ALARHighAI 9/10

Alarum Technologies slumps following FBI probe

Alarum Technologies (Nasdaq: ALAR; TASE: ALAR) shares fell over 70% after the company said some domains tied to its NetNut subsidiary were seized in an FBI investigation. Alarum reported service disruptions and warned of a potential material adverse effect. Google said it disabled accounts linked to alleged malware and degraded NetNut’s proxy network.

$ALARMedAI 8/10

Alarum Technologies stock plunges on FBI probe of subsidiary By Investing.com

Alarum Technologies (NASDAQ:ALAR) shares fell 23.6% in after-hours after reports the FBI is investigating whether Alarum subsidiary NetNut helped link customers’ home internet devices without consent. Bloomberg said the probe has lasted over a year and involves potential links to software called Popa. DOJ said it seized domains tied to NetNut’s proxy infrastructure; Alarum said it was notified and will cooperate.