On July 2, 2026, the FBI and the IRS Criminal Investigation seized hundreds of domains from the NetNut network, while Google simultaneously dismantled the botnet behind it, Popa β consisting of at least 2 million infected devices that had been sold to clients for years as "residential proxies." This is the second major crackdown on a large residential IP provider in six months: in January, IPIDEA was similarly "taken down." This serves as a warning for the market that cannot be ignored: a significant portion of cheap "residential" pools consists of hacked televisions and set-top boxes, and their buyers are at greater risk than they realize.
What Happened to NetNut
NetNut is a residential proxy network built on top of the Popa botnet. According to the Google Threat Intelligence Group (GTIG), the network encompassed at least 2 million devices worldwide, primarily Android set-top boxes, Smart TVs, and streaming boxes. On July 2, a banner from the FBI regarding the seizure appeared on the homepage of netnut.com, and by July 8, a similar banner was displayed on the parent company's website.
Behind NetNut was not an underground group, but a public company β the Israeli Alarum Technologies Ltd, traded on NASDAQ under the ticker ALAR. Following the seizure, its stock plummeted by approximately 67% in a week, down to $2.62. Alarum's lawyer, Omer Weiss, stated that the company "takes this matter seriously and will fully cooperate with law enforcement." In addition to the FBI and Google, Lumen and The Shadowserver Foundation were also involved in the crackdown.
How a "Residential Proxy" Becomes a Botnet
The key mechanism of NetNut is the transformation of ordinary household devices into "always-on" exit nodes without the owner's knowledge. Google and the investigation describe two main infection pathways:
- Pre-installation on cheap devices. Budget TV boxes arrived with proxy software already embedded from the factory and were sold on marketplaces.
- SDK "bundled." Users were prompted to install an application (often for viewing pirated content), and along with the "function," a proxy SDK was installed on the device. GTIG found individual components of NetNut within the large botnet Badbox 2.0, which "packages" proxy plugins into infected firmware.
These IPs were then rented out. In just one week of June 2026, Google counted 316 distinct threat clusters operating through NetNut nodes β ranging from financially motivated cybercriminals to state-sponsored cyber espionage groups. Through foreign "home" addresses, they conducted password spraying, credential stuffing, ad fraud, account takeovers, and scraping. In response, Google disabled associated C2 accounts and configured Play Protect to automatically warn users and disable applications with the NetNut SDK.
Why This Matters to the Average Proxy Buyer
The main unpleasant detail for the market is the NetNut reseller program with whitelabel. The network allowed for the resale of its nodes under different brands, meaning dozens of "independent" residential proxy providers were actually distributing the same botnet under their own names. By purchasing a "residential IP" from an unnamed store, you could very well have been operating through your neighbor's hacked television for years without knowing it.
This is not a one-time story. In January 2026, IPIDEA β at that time the largest residential network β was similarly dismantled, and around 13 brands disappeared along with it: 922 Proxy, LunaProxy, PyProxy, IP2World, PIA S5 Proxy, ABC Proxy, Cherry Proxy, and others. The trend is clear: Google and law enforcement are systematically targeting botnet-based providers, and with each such cleanup, their clients lose access in a single day.
Your risks consist of three parts:
- Legal. Your traffic physically goes through devices over which you have no rights. This is no longer a "gray area," but operating on top of computer crime β with all the questions about owner consent and data processing. The topic of consent and the legality of data collection is only becoming stricter in 2026 β we discussed this in our article on new EDPB guidelines for web scraping and GDPR.
- Operational. Such a pool can be shut down with a single seizure order. Your parsers, account farms, and monitoring systems will come to a halt at the same time, and the money in your balance will disappear along with the provider.
- Technical. "Dirty" IPs from botnets have long been on the radar of anti-fraud systems. They are mass-marked and banned even before the FBI gets to them β how exactly platforms detect residential addresses was described in our analysis of residential proxy detection through IP intelligence.
How to Distinguish a Legal Residential Proxy from a Stolen One
You need to check the provider before payment, not after their domain shows an FBI banner. Hereβs a practical checklist of red flags and green flags for 2026:
- Ask directly about the source of the IP. A legal provider will explain where the pool comes from: explicit user consent, paid SDK partnerships with transparent opt-in, contracts with operators. An answer of "it's our own secret" or silence is a red flag.
- Look for words about ethical sourcing and opt-in β but verify them. The term "ethically sourced" has become a marketing clichΓ©; check if the provider has a clear consent policy and a mechanism for withdrawal, not just a line on their landing page.
- Suspiciously cheap β almost always a botnet. Residential traffic at datacenter prices is never "legitimate." Real costs for a legal pool are factored into the price; dumping usually means that no device owners received a cent for the traffic.
- Check the legal entity and brand history. An unnamed store without a company, address, and public history is a typical whitelabel on someone else's infrastructure. Such "signs" have been disappearing en masse along with IPIDEA and NetNut.
- Assess what will happen in case of a blockage. A serious provider has its own infrastructure, support, and SLA, not just one domain that goes dark with a seizure order.
Thatβs why it makes sense to work with a provider that controls the origin of its pool and does not depend on a single gray network. In ProxyCove residential proxies, IPs are sourced from legal, consented sources β so you get "clean" home addresses without the legal and operational minefield that just exploded under NetNut clients.
What to Do If You've Already Purchased "Residential" Proxies from a Questionable Seller
If your provider has neither a legal entity nor a clear answer about the source of the IP, act as if the next cleanup is about them. Hereβs the course of action:
- Do not tie critical processes to them. Move key parsers and account farms to a provider with a transparent pool origin while the network is still alive. Restoring access after a domain seizure will be impossible.
- Do not keep a large balance. During the takedown of IPIDEA and NetNut, clients' funds burned up along with the service. Top up with small amounts, rather than "a year's worth for a discount."
- Check if your IPs are marked. Run your current addresses through IP reputation services: a high fraud score and labels like "proxy/botnet" mean that platforms already consider you a threat, and bans will only increase.
- Reassess the risk model for accounts. If you were warming valuable accounts through "dirty" IPs, factor in that some of them are already under anti-fraud suspicion, and do not increase the load on them.
The point is not to panic, but to avoid being the last to learn about the source of your traffic from the news. Mobile and datacenter scenarios should also be reconsidered under the same principle of "I understand where my IP comes from and what will happen if the provider is blocked."
Conclusion
The dismantling of NetNut is not just another news story about a botnet. It is a clear signal: the era of cheap "residential" proxies from unclear sources is coming to an end, and it is ending with domain seizures and frozen balances. IPIDEA in January, NetNut in July β the list will continue. The only insurance for a business that seriously depends on proxies is to choose a provider with a transparent IP origin and its own infrastructure in advance, rather than discovering the source of its pool from an FBI banner.
