The FBI, working with Google, Lumen, Shadowserver, and other partners, seized hundreds of domains tied to NetNut, a residential proxy service operated by publicly-traded Israeli company Alarum Technologies. NetNut was linked to the Popa botnet — a network of at least two million compromised devices including smart TVs and streaming boxes — which was used to relay malicious traffic including ad fraud, content scraping, and account takeover attacks. Google's Threat Intelligence Group observed 316 distinct threat actor clusters using NetNut exit nodes in a single week. The takedown is expected to significantly disrupt the cybercrime ecosystem, especially following the earlier seizure of NetNut's biggest competitor, IPIDEA. Experts warn that 42% of LG webOS apps and over 25% of Samsung Tizen apps contain residential proxy SDKs, and advise consumers to stick to name-brand TV devices and avoid unofficial Android TV boxes.