FBI investigates whether alarm device is behind select home devices Clio

FBI investigates whether alarm device is behind select home devices

 Clio

The FBI is investigating whether a subsidiary of data collection company Alarum Technologies Ltd. connected customers’ home internet devices to a network without their consent that people could use to hide their locations, according to documents seen by Bloomberg News and confirmed by people familiar with the matter.

The investigation involves so-called residential proxy networks that route internet traffic to users in a way that appears to come from different locations. Businesses often use these networks to customize their websites for different regions. Sports fans can also use them to live stream games that can only be watched elsewhere.

For more than a year, FBI agents have been examining potential links between NetNut, an Israeli unit of Alarum that sells access to such networks, and Popa software allegedly used to swipe people’s devices, according to records and people familiar with the matter who spoke on condition of anonymity.

The FBI seized multiple Internet domains as part of a “coordinated law enforcement effort targeting infrastructure associated with the NetNut residential proxy platform, its administrators and users,” the U.S. Department of Justice said Thursday.

Alarum legal counsel Omer Weiss said in a statement that the company learned Thursday that the FBI had seized some of its domain names.

“Alarum takes this matter seriously and will cooperate fully with law enforcement to ensure that any misuse of its infrastructure is thoroughly investigated and those responsible are held accountable,” Weiss said in the statement.

The FBI declined to comment on the investigation.

These networks run specialized code installed on everyday devices such as laptops, smartphones, routers and TV streaming boxes. Sometimes device owners agree to install the software in exchange for a few dollars per month. In other cases, devices are registered into residential proxy networks without the owner’s knowledge, cybersecurity experts said.

“I think of residential proxies as being like thousands of anonymous strangers sneaking into your home to gain unlimited internet access,” said Craig Labovitz, technical director at cybersecurity platform Nokia Deepfield. “Most users may not even notice uninvited proxy internet squatters until the police come to investigate cybercrime coming from their home.”

The FBI investigation, which has never been previously reported, is part of a broader law enforcement operation examining the use of residential agent networks. Internet service providers and cybersecurity firms alike have warned that these networks have been used to trick millions of devices around the world.

Residential proxy networks have legitimate business uses. Companies often use them to test products in different regions and scrape website data. But in the hands of hackers, they are like stolen passports. Cybercriminals can use them to locally disguise malicious traffic that could come from virtually anywhere in the world.

The FBI probe involving NetNutis was one of a series of investigations held late last year at a conference on proxy networks in Colorado, where a group of officials from various federal law enforcement agencies took a closer look, according to records and people familiar with the matter. Federal investigations often last years, and many end without allegations of wrongdoing.

Last year, Comcast said, “veneer” The legitimate use of residential proxy networks “exists a shady, deep-rooted supply chain associated with cybercrime and other nefarious activities.” The FBI said March says They are “a standard tool for criminals to impersonate ordinary users online” while making illegal purchases, committing bank fraud and launching other cyber attacks.

Nokia Deepfield’s Labovitz said there are devices powering proxy networks in hundreds of millions of homes around the world, and the vast majority of the devices’ owners are unaware. While it’s difficult to determine the usage of these networks, he said much of the traffic on them appears to be malicious.

Popa specifically can be used to commandeer proxy network devices without the owner’s consent, according to a June analysis by the security firm composite and Querim.

NetNut and Popa “share operational infrastructure and telemetry,” Synthient said in the report. Qurium said it had discovered “multiple technical and historical overlaps” between the technology behind NetNut and the technology behind Popa, which were “unlikely to be coincidences.”

In addition, according to a Report from security company SpurNetNut allegedly required little verification of its customers and allegedly provided access to institutional networks that users never agreed to participate in.Krebs talks safety Studies by Synthient, Qurium, and Spur have been previously reported. Alarum told Krebs on Security that Synthient and Qurium’s reports contained “manifestly inaccurate assertions and flawed inferences rather than verified facts.”

“Netnut operates a network of commercial agents and maintains policies, procedures and technical measures designed to facilitate the lawful and responsible use of its services,” the company told the security publication, adding that it “takes very seriously the appropriate notification and consent mechanisms, conducts customer due diligence, monitors for potential abuse, and takes measures designed to detect and mitigate suspicious or unauthorized activity.”

Popa software has appeared on Android devices around the world, especially smart TV boxes. The number of devices in Popa’s service continues to change, and estimates of its size vary.

Months before researchers at the cybersecurity firm published their findings on NetNut, an agent in the FBI’s Houston field office had been quietly investigating its operations, according to documents and people familiar with the matter. The agent has been evaluating Internet traffic records and interviewing people to try to determine how NetNut was involved in the Popa software, if any, according to people familiar with the matter and records.

There are several versions of Popa software. It’s unclear whether the FBI’s investigation is focused on a specific variant.

In December, law enforcement officials and industry experts showcased the agent’s efforts at a gathering outside Denver, according to people familiar with the matter and records show.

The meeting at the Defense Criminal Investigative Service building was attended by military investigators, agents from several FBI field offices and officials from the agency’s cyber unit in Washington, according to people familiar with the matter and records show. They held a three-day “ResProxy Sprint” to evaluate multiple probes related to the proxy network and examine what actions could be taken against them.

The Defense Criminal Investigative Service declined to comment.

The investigations focus on a market that has emerged by selling and reselling packaged access to millions of devices on proxy networks for a few dollars per gigabyte of data. Analysts estimate that this market arises from US$100 million arrive US$3 billion Sales will continue to grow each year, in part because AI software developers have a huge appetite for data scraped from websites.

“We’ve grown from a tens-of-million-dollar market to a multi-billion-dollar market,” Labovitz said. “A lot of that seems to be thanks to AI companies.”

Acquired by what is now Alarum in 2019, NetNut has become a major player in this market, providing tens of millions of proxy addresses in the system, ensuring “Completely anonymous and fast“.

In May, Alarum reported first-quarter revenue of $11.7 million, up 64% from the same period a year earlier, saying “growth was primarily driven by strong demand for the company’s agency solutions and increased sales of new products.”

photo: Alert technology logo. Photographer: Thomas Fuller/SOPA Images/LightRocket/Getty Images

Copyright 2026 Bloomberg.

Leave a Reply

Your email address will not be published. Required fields are marked *