The Invisible Hijack: Inside the Multi-Million Device ‘Popa’ Botnet

the-invisible-hijack-inside-the-multi-million-device-popa-botnet

For the past four years, an expansive and clandestine Android-based botnet known as Popa has silently turned millions of consumer TV streaming boxes into unwitting conduits for illicit internet traffic. Rather than launching the high-profile, destructive distributed denial-of-service (DDoS) attacks typical of traditional botnets, Popa operates as a sophisticated, persistent communications layer. It serves a singular, lucrative purpose: enabling a global residential proxy network that facilitates everything from mass data scraping and advertising fraud to sophisticated account takeovers.

New research released this week by a coalition of cybersecurity firms has formally linked the Popa botnet to NetNut, a prominent residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]. The findings represent a significant escalation in the ongoing conflict between security researchers and the "proxy-as-a-service" economy, which has become the backbone of the modern AI data-scraping industry.

The Anatomy of the Popa Infrastructure

Popa is not a traditional malware payload; it is a specialized plugin component tethered to the Vo1d botnet, a large-scale campaign that has systematically targeted "no-name" Android TV boxes. These devices, available by the thousands across major e-commerce platforms, are marketed as low-cost alternatives to premium streaming hardware, promising users access to vast libraries of subscription video content for a one-time fee.

However, security experts—including investigators from the FBI—have long warned that these devices arrive pre-bundled with malicious software. Once plugged into a wall socket and connected to a home network, the box effectively becomes a "residential proxy node." This allows third-party customers to route their internet traffic through the device, effectively hiding their true identity and location behind the residential IP address of the unsuspecting consumer.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Unlike simple VPNs, which often have a clear user-facing interface, Popa functions as a background service. It maintains long-lived, encrypted communication tunnels, allowing remote operators to register the device and access it on demand. The impact is profound: when a user’s home network is utilized as a relay, the traffic generated by potentially malicious actors appears to originate from that household.

Chronology of an Investigation

The origins of Popa remained obscure until early 2025, when researchers at the Chinese security firm XLAB identified nine domain names used to orchestrate the movement of compromised devices. These domains served as the "command and control" (C2) infrastructure for the botnet.

In May 2026, the security firm Qurium stumbled upon these same domains while investigating a series of aggressive data-scraping events. Qurium discovered that their client organizations were being targeted by scraping activity distributed evenly across more than 1.4 million unique IP addresses. Further analysis revealed that the control domains—including gmslb[.]net, safernetwork[.]io, tera-home[.]com, and ninjatech[.]io—were hardcoded into dozens of popular, yet pirated, streaming applications such as DooFlix, CyberFlix, Rapid Streamz, and HD/OceanStreams.

While many of these control domains were seized in July 2025 as part of a coordinated effort by Google, HUMAN Security, and Trend Micro to dismantle the Badbox 2.0 botnet (which is closely linked to Vo1d), Popa proved resilient. Immediately following the disruption, the botnet’s operators registered dozens of new control domains. One of these, ninjatech[.]io, pointed directly to a company founded by Moishi Kramer, who serves as the Vice President of Research and Development at NetNut. Kramer’s professional history includes designing the architecture for NetNut before its acquisition by Alarum Technologies.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Data Points and Scalability

The sheer scale of the Popa operation is staggering. Chris Formosa, a senior lead information security engineer for Black Lotus Labs (Lumen Technologies), notes that Popa is uniquely dangerous because of how deeply it is embedded into the broader proxy ecosystem.

"Popa averages between 1.5 million and 2.5 million distinct IP addresses every single day," Formosa stated. "It relies on a backbone of 250 to 300 control nodes to direct its traffic. While it may not be the largest botnet in existence, its integration into various proxy services amplifies its reach significantly."

Nokia Deepfield, which monitors global network traffic, suggests the numbers could be even higher. Jérôme Meyer, a researcher at Nokia, noted that his team is tracking a subset of 26 relay nodes—out of at least 359 known nodes—that collectively handle traffic for between 35,000 and 60,000 clients simultaneously. In a single 24-hour period, these 26 nodes alone facilitated traffic from 750,000 unique sources.

Official Responses and Denials

The link between Popa and NetNut has been met with strong denials from the parties involved. In an email exchange, Moishi Kramer stated that Ninjatech ceased operations approximately five years ago after selling a software development kit (SDK) known as Popa.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

"That code was sold and licensed to third parties including resellers years ago," Kramer explained. "Once software is distributed that way, the original developer has no control over how others later modify, rebrand, or deploy it. I didn’t register the June 2025 domains, and I don’t know who did. I have no control over that infrastructure."

Alarum Technologies also issued a formal rebuttal, characterizing the reports from Synthient and Qurium as containing "demonstrably inaccurate assertions and flawed deductions." The company stated, "The SDKs at issue are designed to facilitate bandwidth-sharing functionality and do not transform user devices into malware-controlled systems. NetNut operates a commercial proxy network and maintains policies and technological measures designed to promote lawful use."

However, this defense is challenged by recent findings from Spur, a proxy-tracking firm. Spur’s research indicates that NetNut’s "Know Your Customer" (KYC) processes are largely performative, allowing individuals to purchase access to residential proxy pools with nothing more than a cryptocurrency payment and a burner email address. Furthermore, Synthient reported that their technical analysis of the Popa SDK revealed outbound traffic patterns explicitly associated with NetNut’s infrastructure, asserting with "high confidence" that Popa devices are actively being used to forward traffic for NetNut clients.

Implications: The AI Scraping Economy

The rise of the Popa botnet is inextricably linked to the modern AI gold rush. Large Language Models (LLMs) require massive datasets to train, and developers are increasingly turning to residential proxies to bypass the security measures implemented by websites to block automated scrapers.

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

"Cloudflare, DataDome, and other security providers throttle or block requests from known datacenter IPs," noted a recent report by Include Security. "The workaround is residential proxies. A scraping job routed through a regular residential connection arrives at the target site from an IP that appears to be a legitimate user."

This demand has transformed ordinary consumer hardware into high-value assets for scrapers. The consequences are widespread. Nonprofit organizations, academic libraries, and scholarly communication platforms have reported increased service disruptions as these "aggressive" bots overwhelm their systems. Research by the Confederation of Open Access Repositories (COAR) found that over 90% of surveyed repositories encounter these disruptive bots at least once a week.

A Growing Threat to Corporate Security

The reach of residential proxy SDKs extends far beyond cheap streaming boxes. They are increasingly found in "productivity" apps, screensavers, and VPNs on mobile devices and even in the workplace. Infoblox recently found that 65% of its corporate customer base—including pharmaceutical, food, banking, and government organizations—were querying residential proxy-related domains.

When these devices are brought into a corporate environment, they expose the enterprise network to external risks. "If threat actors abuse a residential proxy to attack a third party, that third party’s incident response will correctly identify the corporate network as the source," warned Infoblox researchers Nick Sundvall and David Brunsdon. "Untangling that creates significant legal exposure and reputational damage."

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Conclusion: The Need for Regulation

The Popa botnet underscores a critical flaw in the current internet architecture: the lack of transparency regarding how residential IP addresses are leveraged for profit. While some platforms like Amazon and Roku have begun banning proxy-bundled apps, the vast majority of app stores—including those for LG and Samsung smart TVs—remain largely unregulated. Spur’s audit of LG’s webOS found that 42% of available apps contained proxy SDKs, often with no clear mechanism for the user to understand or revoke access.

As the AI economy continues to incentivize the mass scraping of the open web, the pressure on residential IP addresses will only increase. For consumers, the warning is clear: that budget streaming box or "free" app may be costing far more than the price of admission, turning your home internet into a weaponized node in a global, invisible, and highly lucrative proxy network. Security experts conclude that until developers, device manufacturers, and policymakers take decisive action to curb the uncontrolled proliferation of these SDKs, the "Popa" phenomenon will remain a pervasive fixture of the digital landscape.