The global fight against cybercrime secured a major victory this week as the U.S. Federal Bureau of Investigation (FBI), in collaboration with Google and other industry partners, successfully disrupted the NetNut residential proxy network. The massive law enforcement operation targeted a sprawling infrastructure that had hijacked an estimated two million home devices worldwide, turning everyday electronics into rented relays for malicious internet traffic.
Known to threat analysts as the Popa botnet, the network represents a sophisticated evolution in modern cyber threats. For years, bad actors have relied on residential proxy services to disguise their digital footprints, making their traffic appear as ordinary home browsing rather than suspicious datacenter activity. Working with tech giants, the FBI officially seized domains tied to the Popa botnet, replacing the NetNut homepage with a law enforcement seizure notice and striking a crippling blow to syndicates that used the service for credential stuffing, advertising fraud, and widespread ransomware attacks.
FBI and Google Dismantle 2-Million-Device Proxy Network in Major Blow to Global Cybercrime

The operation’s scale highlights a growing vulnerability for consumers, particularly in rapidly digitizing regions. The botnet grew by covertly embedding malicious software development kits (SDKs) into third-party Android apps. Users who installed these seemingly harmless free applications on their smart TVs and streaming boxes unknowingly transformed their devices into “exit nodes.” This allowed attackers to route external traffic through private home networks, effectively masking the origin of the cybercrime and placing the blame on the unwitting device owner.
Following the coordinated takedown, Alarum Technologies—the publicly traded Israeli company that operates NetNut—announced a temporary operational pause of certain network services. The company is currently investigating whether its infrastructure was exploited by third parties for unlawful purposes, acknowledging that continued disruptions could severely impact its financial results and customer service capabilities.
For the African technology sector, this disruption serves as a critical wake-up call. As internet penetration deepens and the adoption of affordable, off-brand smart devices accelerates across the continent, households and small businesses inadvertently become prime targets for botnet recruitment. Consumers are urged to stick to official app stores, avoid suspicious applications that offer cash for “unused bandwidth,” and ensure built-in protections like Google Play Protect remain active.
As international law enforcement continues to dismantle the architecture of global cybercrime, the responsibility also falls on regional businesses and regulators to enforce stricter cybersecurity standards. The NetNut takedown proves that the battleground for digital security is no longer confined to corporate servers—it has moved directly into our living rooms.

















