Which Proxy Providers Are Linked to Botnets? Status of NetNut, IPIDEA, PYPROXY and IPWeb (October 2026)
I test residential pools most days, and since the NetNut seizure in July the first question from buyers has changed. People used to ask how fast a pool was. Now they ask whether a provider is linked to a botnet and whether it will still be online next month. This page answers that for every proxy provider named in a botnet report in 2026, with the date each fact was last checked.
Quick answer: Five proxy networks were publicly tied to botnet-sourced IPs in 2026. NetNut's proxy domains are still seized by the FBI, and the company now presents itself on a new domain, netnut.ai, as web data infrastructure for AI. IPIDEA, disrupted by Google in January, was back to about 10 million daily IPs by July, although most of its brand websites are now suspended. PYPROXY, one of those brands, runs on a domain registered again in August 2026 by a self-described new team. IPWeb was reported on October 1 as running on a backdoor installed on TV boxes, and Dutch police took down a botnet in May that news reports tied to Asocks, while the Asocks website stayed online. Separately, an independent teardown questioned how Infatica's SDK reaches phones.
| Provider | What was found | Who said it | Status, checked Oct 2, 2026 |
| NetNut | Popa SDK in streaming apps and TV boxes; at least 2 million devices | Google, Synthient, FBI | Proxy domains still seized. Relaunched as netnut.ai, pitched as web data for AI. |
| IPIDEA (13 brands) | 600+ apps and 3,075 Windows files enrolling devices; 550+ threat groups in one week | Network back to about 10 million daily IPs (Lumen). Seven brand domains suspended. | |
| PYPROXY | Listed by Google as one of IPIDEA's brands | Domain registered again Aug 7, 2026. Site says a new team runs it. | |
| IPWeb (006IP, YangtuIP) | APSolo backdoor on TV boxes; about 800,000 daily IPs; supplies IPIDEA | Synthient | Report published Oct 1, 2026. No public response. Gateway resold under other brands, e.g. BartProxies. |
| Asocks | Botnet of 200 servers and at least 17 million infected devices, tied to Asocks by NL Times | NL Times | Several servers seized May 2026. Website stayed online. |
How this was checked: each row links to the primary report, and the status column comes from CatProxies' own checks on October 2, 2026, using public DNS, domain registration records, the live websites and Alarum's SEC filings. Being named in a report is not a conviction, none of these companies has been convicted of a crime, and each company's own response is included where one exists.
Is NetNut Still Down?
NetNut's original proxy domains are still seized as of October 2, 2026, but the company is back online under a new domain, netnut.ai, which now markets proxies, scraping APIs and datasets as web data infrastructure for AI.
What CatProxies checked on October 2, 2026
| Domain | Name servers on Oct 2, 2026 | What the site shows |
| netnut.io | ns1.fbi.seized.gov, ns2.fbi.seized.gov | "Seized by the Federal Bureau of Investigation" notice |
| netnut.com | ns1.fbi.seized.gov, ns2.fbi.seized.gov | Same seizure notice |
| netnut.net (former gateway domain) | ns1.fbi.seized.gov, ns2.fbi.seized.gov | Same seizure notice |
| alarum.io | ns1.fbi.seized.gov, ns2.fbi.seized.gov | Same seizure notice |
| netnut.ai | Cloudflare | Live NetNut site, registered July 15, 2026 |

The notice says the domain was seized as part of an action against the NetNut residential proxy platform, "its administrators, and its subscribers." That wording covers customers as well as the operator. No charges against NetNut customers have been announced, and a seizure notice is not a court finding against anyone.
NetNut's new site: netnut.ai
The domain netnut.ai was registered on July 15, 2026, 13 days after the seizure. Its About page says NetNut is a subsidiary of Alarum Technologies and lists the Nasdaq ticker ALAR. The new homepage describes NetNut as "web data infrastructure for the AI era" and leads with scraping APIs, datasets and an LLM scraper rather than the residential proxy network the brand was known for. None of Alarum's SEC filings up to August 27 mentions the new domain, and CatProxies has not tested the service or where its IPs come from.

What NetNut's parent has told investors
Alarum Technologies has filed seven reports about the case with the SEC. On July 3 it said more domains had been seized and that neither it nor NetNut had been formally contacted by any authority. On July 4 it paused traffic through the affected services. On July 13 it said it still did not know the root cause, had hired outside forensic investigators, was cutting about a third of its workforce, and expected any restart to go through a documented legal and compliance review.
The rest of the filings are about lawsuits. A July 22 filing disclosed a shareholder request in a Tel Aviv court to inspect company documents, with a hearing set for December 15, 2026, and a motion to certify a class action claiming up to NIS 120 million. The August 13 filing added a second document request that names NetNut Ltd. itself, with a hearing on December 14, 2026, and a US class action filed in New Jersey on August 5 for investors who bought between March 20, 2025 and July 2, 2026; law firm notices set October 5, 2026 as the deadline to apply as lead plaintiff. On August 27, Alarum delayed its first-half results and said it expects significant operating and net losses.
As of October 2, 2026, no fine or penalty against NetNut or Alarum has been announced by any authority or disclosed in Alarum's filings. The December hearings are civil proceedings brought by shareholders, not criminal cases, and Alarum says it will defend itself in all of them.
What NetNut says about the botnet findings
NetNut rejects them. In its reply printed in full in Synthient's June report, it described itself as a legitimate commercial proxy network with KYC and misuse monitoring. The research rests on a controlled test in which a marked request sent into NetNut's gateway came out of a device Synthient had enrolled in the Popa SDK, and on Qurium's analysis of about 5,000 Popa samples talking to 46 control domains and more than 300 servers. Synthient states the test shows an egress relationship, not what NetNut knew about how the SDK was distributed. CatProxies tested NetNut's pool before the takedown, and the results are in the July NetNut alternative post.
Is IPIDEA Still Working After Google's Takedown?
The network is, but most of its storefronts are not. Google disrupted IPIDEA on January 28, 2026, and Lumen's Black Lotus Labs reports it lost about a third of its traffic, stood up new control servers in late March, moved its devices across by mid-May and passed its previous size in July, at about 10 million distinct IPs per day.
Google's report found more than 600 Android apps and 3,075 Windows files contacting IPIDEA's control domains, and more than 550 threat groups using its exits in a single week. It lists 13 brands run by the same actors: 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, Door VPN, Galleon VPN, IP 2 World, Ipidea, Luna Proxy, PIA S5 Proxy, PY Proxy, Radish VPN and Tab Proxy. Bitsight later measured a 15% to 26% overlap between the IPs of five of those brands and devices infected with the Vo1d, BadBox and RootSTV malware, and Synthient's IPIDEA profile gives its main SDK, PacketSDK, a high consent-risk score based on a random sample of apps. Anyone buying residential proxies from a brand that resells this supply is buying the same devices under another name.
Where IPIDEA's brand websites are now
CatProxies checked the registration records and live sites of the proxy brands Google named on October 2, 2026. "Client hold" means the domain's registrar has suspended it, so the site no longer loads.
| Domain | Registry status | What we found |
| ipidea.net | Client hold | Not reachable |
| 922proxy.com | Client hold, redemption period | Not reachable |
| lunaproxy.com | Client hold | Not reachable |
| piaproxy.com | Client hold | Not reachable |
| 360proxy.com | Client hold | Not reachable |
| cherryproxy.com | Client hold | Not reachable |
| tabproxy.com | Client hold | Not reachable |
| abcproxy.com | Held by the Registrar of Last Resort | Not reachable |
| ip2world.com | Registered again July 12, 2026 through a drop-catching registrar | Live, with an "IP2WORLD IS BACK" banner |
| pyproxy.com | Registered again August 7, 2026 | Live, with a "relaunch sale" and a new-team notice |
Where IPIDEA's IPs come from now
Synthient's October 1, 2026 report says IPWeb, a China-based provider running since 2022, became a core supplier of residential IPs to IPIDEA after the January disruption. Synthient bought TV boxes and IoT devices between January and June 2026 and kept finding the same Java file, which it calls APSolo, installed through pay-per-install deals without consent. It estimates about 800,000 daily active IPs, 26.8% of them in Brazil, and links IPWeb to two white-label brands, 006IP and YangtuIP. Synthient's IPWeb profile names the operator as Unlimited Connection Technology Co., Limited, a Hong Kong company, and its NetNut profile adds that IPWeb infrastructure was seen pointing to a NetNut gateway on one route, which Synthient says does not prove ownership. The report does not show the evidence behind the IPIDEA supply claim, so treat that part as Synthient's assessment.
IPWeb bandwidth is also resold under other brands. Synthient's report shows an archived BartProxies pricing page as an example of IPWeb bandwidth sold at $15 per GB, and public DNS shows the same link at the gateway level. On October 2, 2026, the hostname resipro.bartproxies.com was an alias (a CNAME record) of gate1.ipweb.cc, IPWeb's own gateway, on both Cloudflare's and Google's public resolvers. Reselling another network's bandwidth is common and legal; the open question for any buyer is where the devices behind that gateway come from.
$ dig +short CNAME resipro.bartproxies.com # checked October 2, 2026
gate1.ipweb.cc.IPWeb also let customers reach localhost and private network addresses through the exit device, which attackers used to infect Android devices with debugging left open. Synthient assesses that this helped spread the Jackskid, Katana and SDKC DDoS botnets; the indicators are published on GitHub. For what a large application-layer attack looks like from the receiving end, see the 25 million request L7 DDoS case study.
Are PYPROXY and IPIDEA the Same Company?
Google lists PY Proxy as one of the 13 brands controlled by the actors behind IPIDEA, sharing the same backend servers. The PYPROXY site running today says it is a different team using the same name.
Registration records show pyproxy.com was registered on August 7, 2026, which means the earlier registration ended and the name was registered again months after Google's January action. The Wayback Machine has no copies of the site between January 15 and August 31, 2026, and the January 2026 version named a company, Data Era Limited, that the current site no longer mentions. The new footer states that pyproxy.com is operated by the "PyProxyBack team" after a handover from the original PYPROXY team, and its FAQ says accounts and balances from the previous service were not carried over.

IP2World, another brand on Google's list, shows the same pattern. Its domain was registered again on July 12, 2026, and the relaunched site uses the same page title format as the new pyproxy.com ("Residential, Mobile & ISP Proxies from $0.19/GB"), the same kind of Telegram support channel, and a "1 GB free" first-payment offer. CatProxies could not verify who runs either site now or where their IPs come from, and matching website templates do not prove common ownership.

Is Infatica Legit? What the September 2026 SDK Teardown Found
Infatica is a Singapore-based company that sells proxies openly, and no authority has acted against it or linked it to a botnet. On September 20, 2026, an independent researcher at vasie.dev (archived copy) reverse-engineered its Android SDK and found it inside cracked and modded game APKs, where neither the game studio nor, in practice, the player had agreed to it.

The carriers include modded copies of Stardew Valley, Subway Surfers, Shadow Fight 2 and Hungry Shark from APK sites such as an1.com, 5play and FarsRoid. The studios behind those games never integrated anything; the partner ID that gets paid belongs to whoever repackaged the file. Infatica markets its SDK to developers as a revenue share, and the teardown suggests much of this supply comes from repack sites instead, so the user thinks they installed a game with the ads removed.
Once installed, the SDK runs as a foreground service, records whether the phone is on mobile data or wifi (mobile IPs sell at a premium), and lets the operator choose the DNS resolvers used for customer traffic. Public hosts stay reachable, so abuse lands on the phone owner's IP. Code and scans are in a public repository.

The teardown covers one SDK build and a set of APKs. It contains no device counts and no response from Infatica, and older reviews that call Infatica's network ethically sourced were written before it was published.
Which Other Proxy Networks Were Named in 2026?
| Network | What was reported | Who said it | Level |
| Aisuru, Kimwolf, JackSkid, Mossad | IoT botnets linked to proxy resale; control servers seized | US DOJ, March 2026 | Official action |
| Jaguar, Kookeey, G3Proxy | Tracked as malicious proxy botnet clusters, roughly 0.6 to 2 million daily IPs each | Lumen, July 2026 | Research |
| 922 Proxy, ABC Proxy, IP2World, Luna Proxy, PYPROXY | 15% to 26% of IPs overlapped devices infected with Vo1d, BadBox or RootSTV malware | Bitsight, May 2026 | Research |
| Thordata | Admin hostnames found on a shared domain alongside hostnames named for IPIDEA and several of its brands | OWN Security, Sep 2026 | Research, circumstantial |
| H96 TV boxes | Boxes relay proxy traffic while the TV is on and run ad fraud while it is off | Bitsight via KrebsOnSecurity, July 2026 | Research |
The Thordata row needs context. OWN Security, a French security firm, studied a Hong Kong scraping service in September 2026 that it connects to Thordata through a shared developer account. It found Thordata admin hostnames on a domain, worldrift.com, whose other hostnames carry the names of IPIDEA, IP2World, ABC Proxy, Cherry Proxy, TabProxy and the PacketSDK and EarnSDK kits, and some exit IPs used by that scraping service were classified as part of the IPIDEA pool. OWN Security says this warrants scrutiny without proving a direct link, and Google's IPIDEA list does not include Thordata.
Private seller channels name more brands than this. None of those claims has a public report behind it yet, so they stay out of this page until one does.
Timeline of the main actions
| Date | Event | Source |
| May 29, 2024 | DOJ dismantles 911 S5 and arrests its administrator; about 19 million IPs. | US DOJ |
| Jun 5, 2025 | FBI warns about BadBox 2.0 malware on off-brand Android TV boxes. | FBI IC3 |
| Jan 28, 2026 | Google disrupts IPIDEA and its 13 brands. | Google GTIG |
| Mar 12, 2026 | FBI publishes a warning dedicated to residential proxy networks. | FBI IC3 |
| Mar 19, 2026 | Court-authorized takedown of the Aisuru, Kimwolf, JackSkid and Mossad servers. | US DOJ |
| May 2026 | Dutch police take down a botnet that NL Times ties to Asocks; the website stays online. | The Hacker News |
| Jul 2, 2026 | FBI and IRS-CI seize NetNut's domains; Google cuts at least 2 million devices. | Google GTIG, Alarum |
| Jul 12 to Aug 7, 2026 | ip2world.com and pyproxy.com are registered again; netnut.ai is registered on July 15. | Registration records |
| Sep 20, 2026 | Infatica SDK teardown published. | vasie.dev |
| Oct 1, 2026 | IPWeb report published. | Synthient |

How Do I Check If My Proxy Provider Uses Botnet IPs?
No buyer can fully audit consent, but five checks catch most of the warning signs.
- Ask where the residential IPs come from, in writing. Ask whether the provider owns its network or resells one, how devices are recruited (SDK, paid app, carrier contract), what the device owner sees, and who has audited it. Google's January report says ethical sourcing claims need transparent, auditable proof of consent, so "ethically sourced" on its own is not an answer.
- Check what broke on the takedown dates. If your pool shrank sharply in late January 2026 or between July 2 and July 4, 2026, your provider may have been reselling IPIDEA or NetNut capacity.
- Test a sample of exits. Run 50 or more exits through the free CatProxies proxy checker and look at the IP type and ASN of each one. A residential plan full of hosting networks is a warning sign.
- Ask whether exit nodes block private and loopback addresses. IPWeb's failure to block them is what let attackers reach the devices behind it.
- Compare two providers for overlap. Two independent pools should barely share any exits. The test below takes a few minutes.
A simple overlap test
The script below pulls 200 exits from each of two plans through a public IP echo service and counts how many IPs and /24 ranges they share. Set both plans to the same country, and expect it to use a few megabytes of traffic.
# Compare the exit IPs of two proxy plans. Use the same country on both.
import requests
def exits(proxy_url, n=200):
ips = set()
for _ in range(n):
try:
r = requests.get("https://api.ipify.org", timeout=15,
proxies={"http": proxy_url, "https": proxy_url})
ips.add(r.text.strip())
except requests.RequestException:
pass
return ips
a = exits("http://USER:PASS@gateway-of-provider-a:PORT")
b = exits("http://USER:PASS@gateway-of-provider-b:PORT")
net24 = lambda s: {ip.rsplit(".", 1)[0] for ip in s}
print(len(a), "unique exits from A,", len(b), "from B")
print(len(a & b), "shared IPs,", len(net24(a) & net24(b)), "shared /24 ranges")Two independent pools sampled this way should share close to zero IPs. A handful of shared /24 ranges is normal inside large carriers, while dozens of identical IPs means both brands most likely resell the same upstream network. The test shows overlap, not consent.
How widely residential IPs are resold
In August 2026, CatProxies matched 1,693 residential exit IPs from 17 pool samples across several commercial providers against Synthient's catalog of which proxy brands list each IP. Only 22% appeared in fewer than 10 brands' catalogs, and 38% appeared in more than 20. An IP shared by dozens of brands gets flagged faster, which is one reason proxies still get CAPTCHAs, and it means a problem upstream reaches every brand reselling it. Public DNS shows the same thing at the gateway level, where many small brands' gateway hostnames resolve to the same handful of servers or point straight at a larger network's gateway, as resipro.bartproxies.com does with IPWeb.

What Should I Do If My Proxy Provider Was Taken Down?
Treat it as an open incident rather than waiting for an announcement. NetNut resurfaced on a new domain after the seizure, and the relaunched PYPROXY says old balances were not carried over.
- Export invoices, payment records, usage logs and support conversations while dashboards still load. They matter for any refund or card dispute.
- List every script, browser profile and tool that holds the provider's hostname or credentials, and rotate those credentials.
- Move a small share of traffic to a replacement first, with the same targets and retry rules, and compare usable responses and session stability.
- Ask the replacement the sourcing questions above in writing, and keep the answers.
- Remove old credentials, IP allowlists and gateway entries once the move is finished.
Which Proxy Types Don't Depend on Home Devices?
Static ISP, dedicated ISP, datacenter and IPv6 proxies run on server infrastructure, so takedowns of phone and TV-box botnets do not remove them. Rotating residential pools remain the only option for wide home-IP coverage, which is why their sourcing deserves the checks above.
| If the task needs | Use | Why it fits |
| Many home IPs across many countries or cities | Rotating residential proxies | Only residential pools give wide geo coverage; run the checks above before scaling |
| Logins and sessions that last hours or days | Static ISP proxies | IP ranges assigned by internet providers to hosted servers, not consumer devices |
| One clean address per account, not shared | Dedicated ISP proxies | Not shared with other users; filtered plans are screened for a low fraud score |
| High-volume work on sites that allow datacenter traffic | Datacenter proxies | Server infrastructure only, lowest cost per request |
Static ISP pools are smaller and cover fewer locations, and some sites detect ISP ranges; the trade-offs are covered in ISP vs residential proxies. A good first step this week is to run 50 exits from your current plan through a proxy checker, run the overlap test against a second provider, and move long sessions to a small static ISP plan if the sourcing answers come back vague.
Frequently Asked Questions
Is NetNut back online?
Partly. Its original domains (netnut.io, netnut.com, netnut.net) still showed the FBI seizure notice on October 2, 2026, but a new site at netnut.ai, registered July 15, 2026, presents NetNut as an Alarum subsidiary selling proxies, scraping APIs and datasets for AI companies.
Was NetNut fined?
No fine or penalty had been announced as of October 2, 2026. Alarum faces shareholder lawsuits in the US and Israel and two court hearings in Tel Aviv on December 14 and 15, 2026, all civil proceedings.
Can NetNut customers get in trouble?
No charges against NetNut customers have been announced. The FBI notice on netnut.io does say the action was taken against the platform, its administrators and its subscribers, so customers should keep their records and stop routing traffic through any service linked to the seized network. This is general information, not legal advice.
Was NetNut a botnet?
Google and several security firms describe the Popa network behind NetNut as a botnet of at least 2 million devices. NetNut and Alarum reject the findings and say NetNut is a legitimate proxy network with customer checks. No court has ruled on the question.
Did PYPROXY customers keep their balances?
According to the relaunched pyproxy.com, no. Its FAQ says the site is back under new operation and that accounts and balances from the previous service were not carried over. The domain itself was registered again on August 7, 2026.
What is IPWeb?
IPWeb is a residential proxy service at ipweb.cc that Synthient says is operated by a Hong Kong company and has run since 2022. Synthient's October 1, 2026 report says its pool comes from TV boxes and IoT devices infected with a backdoor called APSolo, with about 800,000 daily active IPs, and that it now supplies IPIDEA.
Is a residential IP automatically safe?
No. A residential classification only says which network owns the address. Synthient's Popa report warns that traffic from a residential IP should not be trusted for that reason alone, and the FBI lists residential proxies as a tool for account takeovers and brute force attacks.
Are expensive proxies more likely to be cleanly sourced?
Not necessarily. The IPWeb report shows bandwidth bought at about $0.40 per GB being resold for up to $15 per GB. Price reflects the seller's margin and says nothing about where the devices came from.
How do I know if my TV box is being used as a proxy?
Signs include slow internet when nothing is playing, constant upload from the box in your router's device list, and CAPTCHAs on most sites from home. Off-brand boxes without Play Protect certification carry the most risk, because malware like BadBox 2.0 ships in the firmware; Google lists certified partners on android.com/tv. You can also look up your public IP on the free IP lookup tool to see whether it is flagged as a proxy.
Corrections and Right of Reply
This page summarizes public research, official records and checks anyone can repeat. It does not accuse any company of a crime, and it reports each company's denial where one exists. If you represent a company named here and something is inaccurate or out of date, send the details and a source through the CatProxies contact page. The page will be reviewed, corrected where needed, and the change noted in the changelog.
Sources
- Google GTIG, continued disruption of residential proxy networks (Jul 2, 2026)
- Google GTIG, disrupting the largest residential proxy network (Jan 2026)
- Synthient, IPWeb: Peering from Within (Oct 1, 2026)
- Synthient, Popa: From Sourcing to Distribution (Jun 18, 2026)
- Synthient provider profiles: IPWeb, NetNut, IPIDEA (updated Sep 28, 2026)
- Archived BartProxies pricing page cited by Synthient (Aug 31, 2026)
- vasie.dev, Taking apart Infatica (Sep 20, 2026) and archived copy
- OWN Security, From residential IPs to resold data (Sep 29, 2026)
- Lumen Black Lotus Labs, Symbiotic Parasites (Jul 24, 2026)
- Qurium, Finding Popa (Jun 18, 2026)
- Bitsight, residential proxy services and malware ecosystems (May 7, 2026)
- KrebsOnSecurity, FBI seizes NetNut proxy platform (Jul 2, 2026)
- Reuters, Google disrupts NetNut proxy network (Jul 2, 2026)
- Bloomberg Law, FBI probes whether Alarum unit is behind co-opted home devices (Jul 2, 2026)
- Alarum Technologies SEC filings: Jul 2, Jul 3, Jul 4, Jul 13, Jul 22, Aug 13, Aug 27
- Class action notice, Kirby McInerney LLP via GlobeNewswire (Sep 16, 2026)
- Domain registration records (RDAP): netnut.ai, pyproxy.com, ip2world.com; archived January 2026 pyproxy.com
- The Hacker News, Dutch authorities dismantle Asocks botnet (May 2026) and TechRadar (May 2026)
- FBI IC3, I-031226-PSA on residential proxy networks (Mar 12, 2026)
- US DOJ, Aisuru, Kimwolf, JackSkid and Mossad disruption (Mar 19, 2026)
- KrebsOnSecurity, LG to ban residential proxies from smart TV apps (Jul 21, 2026)
Changelog
October 2, 2026: first published. Domain, registration and website checks run the same day. The status tables will be re-checked and re-dated at least monthly, and new developments will be added here with their date.
