FBI and Google Disrupt NetNut Botnet That Rented 2 Million Home Devices to Spies
The FBI and Google, with partners including Lumen Technologies and the IRS, disrupted NetNut, a residential proxy botnet run by Alarum Technologies (Nasdaq: ALAR). The network enrolled an estimated 2 million home devices and was linked to 316 threat clusters in June 2026. Actions included disabling Google C2, updating Play Protect, and seizing hundreds of domains.
How this was made

The 30-second read
Why it matters
The takedown targets multiple layers: disabling Google-based C2, seizing domains, and updating Play Protect to detect/disable NetNut-containing apps—reducing botnet operability and increasing legal exposure for the operator.
Market read
For traders, the key is that the article ties a publicly listed operator (ALAR) to a large-scale law-enforcement takedown, implying elevated litigation/regulatory and potential business disruption risk.
What to watch
The article provides no quantified financial impact, no explicit charges/settlement, and the body is truncated at the end—future filings or court documents could change the risk profile materially.
Background
NetNut (“Popa”) is described as a residential proxy botnet that enrolled ~2M consumer devices via SDKs embedded in seemingly legitimate Android/TV apps.
Ticker impact
Article says NetNut botnet was operated by Alarum Technologies and that the FBI seized domains and disrupted its command-and-control infrastructure.
Downside bias on ALAR on enforcement headlines; magnitude uncertain without financial disclosures.
The piece links Alarum (ALAR) to NetNut and describes coordinated takedown steps (domain seizures, C2 disruption, app blocking), which typically increase litigation/regulatory and business-continuity risk.
Market effects
Highlights heightened scrutiny of residential proxy/SDK distribution models and increased platform enforcement (Play Protect), which can pressure similar threat-adjacent business models.
US-led law enforcement action (FBI/IRS) suggests cross-border enforcement risk for operators tied to US infrastructure.
Google ecosystem controls (Play Protect, GTIG intelligence) indicate global takedown capability and faster remediation across Android/consumer devices.
Counterpoint
ALAR may be only the corporate operator of the infrastructure while the market may already price in cyber-risk; stock reaction could be muted if investors view it as non-material to financials.
Key entities
- malware/botnetNetNut
Residential proxy botnet enrolling consumer devices and routing traffic for cybercriminal/espionage activity.
- companyAlarum Technologies
Israeli company described as publicly listed on Nasdaq and identified as the operator behind NetNut.
- law enforcementFBI
Executed domain seizures and coordinated disruption with Google and other partners.
- platform/securityGoogle (GTIG)
Disabled C2 accounts/services, shared intelligence, and updated Play Protect to block NetNut SDK apps.
- partnersLumen Technologies / Shadowserver Foundation / IRS Criminal Investigation
Participated in the coordinated disruption and/or intelligence sharing.



