‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Your office Wi-Fi may already be a proxy node.

AI-generated illustration depicting incident for the story: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

A sprawling botnet built from dodgy TV boxes has been tied to a NASDAQ-listed proxy firm, and the bigger lesson is that residential proxies are quietly turning up inside corporate networks.

Summary

  • Researchers from several firms have linked Popa, an Android-based botnet running on millions of cheap TV boxes, to NetNut, a residential proxy provider owned by publicly-traded Israeli firm Alarum Technologies (NASDAQ: ALAR).
  • Popa is a plugin tied to the Vo1d botnet. Infected devices relay other people’s internet traffic for ad fraud, account takeovers and large-scale AI data scraping.
  • Estimates put Popa at roughly 1.5–2.5 million active IP addresses a day, and because NetNut proxies are resold widely, those addresses surface across dozens of other services.
  • Alarum disputes the “botnet” label and says NetNut runs a lawful, consent-based proxy network with KYC checks. Trackers like Spur say meaningful KYC is largely absent, especially through resellers.
  • The CISO angle isn’t the TV boxes — it’s that residential proxy SDKs are showing up on employee and corporate devices, exposing your IP space to someone else’s traffic.

What happened

For about four years, a botnet called Popa has been running on millions of no-name, Android-based streaming boxes — the kind sold online with a promise of free access to hundreds of paid streaming services. This week, security researchers from multiple firms concluded the botnet is connected to NetNut, a “residential proxy” provider owned by Alarum Technologies.

Unlike a classic botnet built to launch denial-of-service attacks, Popa is designed to do one thing well: keep a device quietly registered and reachable so that traffic can be tunnelled through it on demand. In practice, that turns someone’s lounge-room TV into an exit point for whoever is paying for proxy access.

The trail started with a 2025 report from Chinese security firm XLAB that flagged a handful of control domains. Security firm Qurium picked up the same domains while investigating aggressive data-scraping that hit its hosted clients in May 2026 — activity spread across more than 1.4 million IP addresses. One control domain stood out: ninjatech[.]io, owned by a company founded by a NetNut VP of research and development.

That executive told Krebs the relevant software development kit was sold and licensed to third parties years ago, and that once code is distributed that way the original developer has “no control over how others later modify, rebrand, or deploy it.” He says neither he nor NetNut operates the infrastructure described as Popa.

Other researchers reached a firmer conclusion. Proxy-tracking firm Synthient said its analysis of the Popa SDK found outbound traffic clearly tied to NetNut, and assessed “with high confidence” that Popa devices forward traffic for NetNut clients. Alarum, for its part, called the reports “demonstrably inaccurate” and rejected the botnet characterisation, saying its SDKs simply enable bandwidth-sharing with notice, consent and customer due diligence.

There’s a consent gap worth noting, though. Synthient found that of more than 20 genuine Popa publishers it analysed, none asked users for consent before enrolling their device.

How big is it

Chris Formosa of Lumen’s Black Lotus Labs said the real danger isn’t raw size but reach — because so many other services resell NetNut, Popa addresses turn up “all over the ecosystem.” Nokia Deepfield’s Jérôme Meyer suggested the device population may be larger than current estimates, telling Krebs he saw 750,000 unique sources in 24 hours from just a subset of relay nodes.

This all feeds the AI data-scraping economy. Residential proxies let scrapers route requests through real home connections, sidestepping the blocks that cloud and datacenter IPs run into. The result is relentless scraping that has overwhelmed libraries, universities and nonprofits — and spawned dozens of copyright lawsuits.

Why it matters for CISOs

The headline is about TV boxes, but the exposure sits much closer to home. Residential proxy SDKs aren’t confined to dodgy hardware — they’re embedded in free mobile apps, VPNs, screensavers and “productivity” tools that staff install on personal and work devices. Smart TVs are riddled with them too: Spur found proxy SDKs in more than 42% of LG webOS apps and over a quarter of Samsung Tizen apps it scanned.

Infoblox reported that 65% of its customer base queried residential proxy domains, and that more than 60% of its government and banking customers did the same. That means external parties may be routing traffic through your address space.

The attribution risk is the part that should keep you up at night. As Infoblox researchers put it, if a threat actor abuses a residential proxy beaconing from your network to attack someone else, the victim’s incident responders will — correctly — point the finger at your IP. Proving you were the conduit, not the attacker, costs time, creates legal exposure and dents your reputation.

What to do now

  • Hunt for proxy indicators in DNS. Use threat-intel feeds (Infoblox, Spur and others publish residential-proxy domain indicators) to flag and block beaconing to known proxy control and relay domains.
  • Treat residential proxy traffic as a managed risk, not background noise. Build detections around the behaviour and review egress for unexpected long-lived tunnels.
  • Tighten BYOD and app policy. Free VPNs, streaming apps, screensavers and utility apps are common SDK carriers — restrict them on managed devices and educate staff on what “sharing your connection” actually means.
  • Look beyond laptops. Smart TVs, streaming sticks and other IoT on corporate, lab or home-office networks can be proxy nodes; segment them away from sensitive systems.
  • Document your position. Given the legal and reputational exposure, make sure IR runbooks account for “our IP, not our traffic” scenarios so you can respond to third-party complaints quickly.

Sources