Popa Botnet Ties Publicly-Traded Israeli Firm to Android TV Box Proxy Network

Security researchers expose hidden infrastructure connecting millions of compromised Android TV boxes to a publicly-traded Israeli firm.

By Central
The Popa botnet transforms consumer Android TV boxes into proxy nodes for ad fraud and data scraping.
Highlights
  • The Popa botnet uses pre-installed malware on cheap Android TV boxes to create a residential proxy network.
  • Evidence links the Popa SDK to NetNut, a proxy service owned by Alarum Technologies, a NASDAQ-listed company.
  • Synthient's analysis confirms Popa devices forward traffic to NetNut clients, contradicting Alarum's denial.

For the past four years, the Popa botnet has quietly transformed millions of consumer Android TV boxes into unwilling relay nodes for advertising fraud, account takeover attempts, and mass data-scraping operations. This week, a multi-firm investigation culminated in a significant attribution: the botnet is tied to NetNut, a residential proxy provider operated by the publicly-traded Israeli company Alarum Technologies Ltd [NASDAQ: ALAR]. The finding connects a sophisticated, large-scale proxy network directly to a publicly-listed corporation, raising urgent questions about accountability, user consent, and the hidden infrastructure powering the AI scraping economy.

What Is the Popa Botnet and How Does It Work?

Unlike traditional botnets designed for destructive distributed denial-of-service attacks or ransomware deployment, Popa serves a singular, commercial purpose. It implements a persistent communications layer that registers a device, maintains long-lived encrypted connections, and opens communication tunnels on demand. This architecture effectively turns an unsuspecting user’s home internet connection into a routable node for paying proxy customers. Popa is understood to be a plugin component of the Vo1d botnet, a large-scale malware campaign that targets unofficial Android-based TV boxes. These devices, sold under thousands of brand names on major e-commerce platforms, advertise access to hundreds of subscription video services for a one-time fee. In reality, they come pre-installed with software that enrolls the user’s home IP address into a residential proxy network, often without meaningful consent.

Evidence Linking Popa to NetNut and Alarum Technologies

The investigation into Popa’s origins began with a 2025 report from the Chinese security firm XLAB, which identified nine domain names used to register and direct compromised devices. Building on that work, the security firm Qurium discovered that several dozen control domains for Popa were hosted in lockstep across multiple internet addresses. Among them was ninjatech[.]io, a domain owned by Moishi Kramer, whose LinkedIn profile lists him as vice president of research and development at NetNut. Kramer’s profile states he helped build NetNut from the ground up before it was acquired by Alarum Technologies. When contacted, Kramer stated that Ninjatech ceased operations approximately five years ago and sold an SDK called Popa to third parties. He asserted that neither he nor NetNut operates the current Popa infrastructure. However, a separate report released today by the proxy-tracking firm Synthient contradicts that claim. Synthient stated that a recent analysis of the Popa SDK revealed outbound traffic clearly associated with NetNut. “The research team assesses with high confidence that devices running Popa forward traffic from Netnut clients,” Synthient wrote. “This proves without a shadow of a doubt that Popa actively continues to be used by NetNut as part of their proxy pool.”

Alarum’s Response and Researcher Rebuttals

Alarum Technologies rejected the findings, stating that the reports contained “demonstrably inaccurate assertions and flawed deductions rather than verified facts.” The company said the SDKs in question are designed for bandwidth-sharing functionality and do not transform devices into malware-controlled systems. Alarum emphasized that NetNut maintains policies for consent, customer due diligence, and misuse monitoring, including KYC checks. However, the proxy tracking service Spur pushed back sharply. In a report released on June 8, Spur asserted that NetNut does not require meaningful KYC procedures before allowing customers to purchase proxy access. “An individual can sign up, pay, and route traffic through partner address space, including space belonging to institutions whose users never opted in,” Spur wrote. “The ‘verified corporations only’ claim is simply marketing for bandwidth sellers, not an access control on who actually uses the proxies.” Spur further noted that downstream white-label resellers repackage the same proxy pool with little to no scrutiny, allowing access with a burner email and a small cryptocurrency payment.

The Scale of the Popa Botnet: Millions of IPs Daily

The sheer size of the Popa botnet underscores its impact. Chris Formosa, senior lead information security engineer at Black Lotus Labs (a division of Lumen Technologies), estimates that Popa averages between 1.5 million and 2.5 million distinct IP addresses each day, coordinated by 250 to 300 command-and-control addresses. “What especially makes Popa dangerous is just how widely used NetNut is for reselling and sharing,” Formosa said. “So these Popa IPs appear in tons of different services all over the ecosystem, which makes it one of the most problematic and dangerous proxy botnets on the market currently.” Jérôme Meyer, a security researcher at Nokia Deepfield, suggests the actual device count may be significantly higher. Nokia is monitoring 26 of at least 359 known relay nodes, estimating each handles between 35,000 and 60,000 clients simultaneously. On a subset of 26 relay nodes, Meyer observed 750,000 unique sources in a single 24-hour period.

How Proxy Networks Fuel the AI Data Scraping Economy

The Popa botnet and networks like it have become critical infrastructure for the AI industry. AI companies depend on massive volumes of web-scraped content for pre-training, retrieval, and agent grounding. However, major bot mitigation services like Cloudflare, DataDome, and HUMAN block or throttle requests from known cloud IPs. The workaround is residential proxies. Routing a scraping job through a Comcast or T-Mobile subscriber’s connection makes the request appear to come from a legitimate home user. This relentless scraping has spawned more than 70 copyright infringement lawsuits against major tech companies. The irony is acute: much of the scraping is powered by proxy services intimately tied to unofficial Android TV boxes and SDKs designed for streaming pirated content. The scraping activity is often so aggressive that it overwhelms targeted websites. A survey by the Confederation of Open Access Repositories found that over 90 percent of respondents encounter aggressive bots more than once a week, leading to slowdowns and service outages. Brendan O’Connell, platform manager at the Directory of Open Access Journals, noted that “the current investor-fueled AI startup craze means there are now thousands of well-funded companies developing and deploying their own scraping tools to train AI models, alongside existing major players like OpenAI and Google.”

Beyond TV Boxes: LG and Samsung Smart TVs Are Affected Too

The problem extends well beyond cheap, no-name streaming boxes. Spur recently scraped the LG and Samsung app stores and found a startling prevalence of proxy SDKs. More than 42 percent of apps available for download via LG’s webOS operating system include SDKs that turn the television into an always-on residential proxy node. Over a quarter of apps for Samsung’s Tizen operating system had similar components. This means that even households that have never purchased an unofficial TV box can have their smart TV enrolled in a proxy network simply by downloading a seemingly innocuous app. “Privacy-policy disclosure is the wrong control surface for a TV,” Include Security wrote in a June report. “It is hard to scroll through a legal document navigated by arrow keys on a remote, and the in-app consent dialog doesn’t convey that a paying customer is about to route their scraping traffic through the user’s home internet.” Sean Simmons, head of research at Spur, added that most people lack a mental model for what it means to sell access to their residential IP address. “A one-time prompt navigated with a remote can disappear into the setup flow, while the app keeps monetizing the connection long after anyone remembers what they accepted,” Simmons said. He noted that Amazon and Roku have already drawn lines against residential proxy providers, and urged LG and Samsung to follow suit.

Residential Proxies in the Enterprise: A Growing Blind Spot

Residential proxy infections are not limited to home entertainment devices. The security firm Infoblox found that 65 percent of its customer base was querying one or more residential proxy-related domains. The firm observed a 25 percent increase in such queries over 2025, reaching over 500 billion per month. Over 90 percent of pharmaceutical and food and beverage customers, and over 60 percent of government and banking customers, had queried residential proxy indicators. The risk is concrete: if a threat actor abuses a residential proxy on an employee’s device to attack a third party, the third party’s incident response will correctly identify the organization’s IP space as the source. “Untangling that, by proving that you were the conduit and not the threat actor, costs time, creates legal exposure, and can damage your reputation,” Infoblox researchers warned.

What Affected Users and Organizations Should Do Now

For consumers who may own an unofficial Android TV box, the most effective step is to disconnect the device from the network immediately and replace it with a reputable streaming device from a known manufacturer. Users should audit all apps installed on their smart TVs and remove any that are not from a trusted source, particularly free streaming apps, VPNs, or utility apps that request unusual permissions. For organizations, the priority is to implement network-level monitoring to detect outbound traffic to known residential proxy domains and command-and-control infrastructure. Endpoint detection and response solutions should be configured to flag devices that beacon to such domains, and a network access control policy should restrict the use of unmanaged or personal devices on corporate networks. When choosing a security solution to address this threat category, organizations should look for a network detection and response platform that provides visibility into DNS queries and TLS handshakes, enabling the identification of proxy-related traffic patterns. Regardless of the specific approach, the most critical action is to establish a baseline of normal network behavior and actively monitor for the distinct traffic signatures associated with residential proxy SDKs.

Share This Article